Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 29
Repositories
- atx-forensic Public
Reader/decoder for Apple ATX (AAPL) texture-image containers — iOS UI image caches (PosterBoard snapshots, wallpapers, contact posters, Animoji avatars). Decodes ASTC (incl. LZFSE-wrapped) to RGBA.
SecurityRonin/atx-forensic’s past year of commit activity - apfs-forensic Public
Apple File System (APFS) forensic library — from-scratch pure-Rust reader (apfs-core) + anomaly analyzer (apfs-forensic) for container, volume, snapshot, encryption and sealed-volume structures. Panic-free, no runtime deps. Design + scaffold; implementation in progress.
SecurityRonin/apfs-forensic’s past year of commit activity - lnk-forensic Public
Windows Shell Link (.lnk) forensics — parse target path, volume serial, MAC times, tracker machine ID; detect removable-media and network targets. Pure Rust. (JumpLists in v0.2.)
SecurityRonin/lnk-forensic’s past year of commit activity - ntfs-forensic Public
From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe
SecurityRonin/ntfs-forensic’s past year of commit activity - mbr-partition-forensic Public
Forensic MBR analyzer: graded anomaly findings (structural, gap/slack carving, wipe & bootkit detection, CHS/LBA & GPT/VBR cross-checks) on a pure read-only MBR parser — Rust crates mbr-partition-forensic + mbr-partition-core
SecurityRonin/mbr-partition-forensic’s past year of commit activity - shellhist-forensic Public
Shell command-history forensic library suite — parse bash, zsh, fish, and PowerShell PSReadLine history; detect history clearing, back-dated entries, and download-pipe-to-shell. Pure Rust, no runtime deps.
SecurityRonin/shellhist-forensic’s past year of commit activity - vmdk-forensic Public
Pure-Rust VMware VMDK toolkit: vmdk-core reader (imported as vmdk; recovers damaged disks via the redundant grain directory) + vmdk-forensic analyzer (RGD adjudication, dangling-pointer & provenance findings)
SecurityRonin/vmdk-forensic’s past year of commit activity - vhdx-forensic Public
Pure-Rust VHDX (Hyper-V) virtual-disk reader and forensic integrity analyzer: a hardened Read+Seek container reader (vhdx-core) plus a 63-code tamper/anomaly auditor with in-memory repair (vhdx-forensic) for DFIR.
SecurityRonin/vhdx-forensic’s past year of commit activity - snss-forensic Public
Chromium/Brave/Edge SNSS session-file forensic decoder — panic-free, read-only; validates the SNSS command stream, decodes navigation base::Pickle payloads, replays per-window tab state. No runtime deps.
SecurityRonin/snss-forensic’s past year of commit activity
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…