awesome-forensics
⭐️ A curated list of awesome forensic analysis tools and resources
https://github.com/Cugu/awesome-forensics
Last synced: 18 days ago
JSON representation
-
Tools
-
Windows Artifacts
- python-evt - Pure Python parser for classic Windows Event Log files (.evt)
- RegRipper3.0 - RegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis
- RegRippy - A framework for reading and extracting useful forensics data from Windows registry hives
- MFTExtractor - MFT-Parser
- MFTMactime - MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all.
- MFT-Parsers - Comparison of MFT-Parsers
- NTFS journal parser
- NTFSTool - Complete NTFS forensics tool
- NTFS USN Journal parser
- RecuperaBit - Reconstruct and recover NTFS data
- python-ntfs - NTFS analysis
- MFTExtractor - MFT-Parser
-
Sub Categories
Acquisition
23
Windows Artifacts
21
Frameworks
17
Labs
13
CTFs and Challenges
11
Internet Artifacts
9
Metadata Forensics
8
Mobile Forensics
8
Steganography
7
OS X Forensics
7
Imaging
7
Live Forensics
7
IOC Scanner
6
Blogs
6
Memory Forensics
6
Distributions
5
Timeline Analysis
5
Carving
5
Disk image handling
5
Books
5
Network Forensics
5
Web
4
File System Corpora
4
Other
4
Management
4
Picture Analysis
3
Docker Forensics
2
Decryption
2
Keywords
dfir
29
forensics
26
security
21
incident-response
17
digital-forensics
11
python
9
awesome
9
awesome-list
8
cybersecurity
7
linux
6
forensic-analysis
5
malware-analysis
5
rust
4
threat-hunting
4
ntfs
4
list
4
forensics-tools
4
intrusion-detection
3
memory-forensics
3
blueteam
3
malware
3
windows
3
parser
3
yara
3
forensic
3
ioc
3
ios
2
solaris
2
shell
2
disk
2
dfir-automation
2
script
2
openbsd
2
graph
2
forensics-investigations
2
investigation
2
automation
2
computer-forensics
2
lab
2
infosec
2
freebsd
2
macos
2
live-response
2
incident-management
2
owasp
2
security-automation
2
ctf
2
forensic-tools
2
mft
2
dynamic-analysis
2