Change the repository type filter
All
Repositories list
121 repositories
peira
Publicforensicnomicon
PublicDFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offli…sqlite-forensic
PublicRead-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version hi…fleet-ci
Publicforensic-vfs-engine
PublicThe forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-i…forensic-vfs-mount
Publicxpress-huffman
PublicPure-Rust, panic-free decompressor for Microsoft Xpress-Huffman ([MS-XCA] §2.2.4) — the codec behind Win10+ prefetch, hiberfil.sys, SMB3 and registry-hive compr…lzo
PublicGPL-free, safe, no_std pure-Rust LZO1X decompressor — decode lzo1x_1 / lzo1x_999 streams (lzop, kernel/initramfs, btrfs, liblzo2) with zero C, zero dependencies…lzvn
Publicelephant-diffuser
PublicThe BitLocker Elephant Diffuser (Diffuser A + Diffuser B + sector-key XOR) in pure Rust — the format primitive with no ecosystem crate, validated in-situ agains…4n6mount
PublicMount forensic disk images, archives & memory dumps as a filesystem on Linux/macOS/Windows — ext4/NTFS/exFAT/HFS+/APFS/ISO, EWF/VMDK/AFF4, AD1, zip/7z/tar, LiME…hfsplus-forensic
Publicstate-history-forensic
PublicState-history forensic vocabulary — zero-dependency [H] KNOWLEDGE-tier types and traits lifting each forensic navigation primitive to a time-indexed variant. No…udf-forensic
Publicforensic-hashdb
PublicFile hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SH…disk-forensic
Publicuseract-forensic
PublicUser-activity forensics — unify shell history, peripheral connections (and v0.2: LNK/shellbags/SRUM/UserAssist/MRU) into one per-user timeline with cross-source…blob-decoder
Publiccfb-forensic
PublicOLE/CFB ([MS-CFB]) forensic analyzer — carves compound files for orphaned (deleted) directory entries, free-sector + slack residue, and structural tamper tells.…usb-forensic
PublicUSB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, …shellitem
PublicWindows Shell Item / ITEMIDLIST (PIDL) parser — decode .lnk LinkTargetIDList and registry ShellBags into typed items + a reconstructed path. A reusable forensic…safe-decode
Publicjsonguard
PublicSecure output sanitization and input inspection for JSON/JSONL, CSV, and TSV — guards against formula injection, bidi-override, control-character, and encoding …safe-read
PublicPanic-free bounded integer readers over untrusted byte slices (no_std, no deps)forensic-carve
PublicFleet carving contract + single-pass sweep engine: signature detection over unallocated/memory regions dispatched to per-format carvers.timeglyph
PublicDecode, identify & encode forensic timestamps — every reading ranked, scored, and cited — plus a timezone/DST/leap-aware reference calendar for interpreting the…shrinkpath
Publicjournald-forensic
PublicFrom-scratch systemd journal (.journal) forensic reader — parse entries without journalctl/systemd, carve from unallocated space, and flag tampering (sequence g…prop-window
Publicblazehash
PublicForensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdee…
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.