Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 24
Repositories
- forensicnomicon Public
DFIR catalog: 6,551 forensic artifacts, LOL/LOFL binaries, abusable sites — query via 4n6query CLI or Rust library
SecurityRonin/forensicnomicon’s past year of commit activity - chat4n6 Public
Forensic extraction for WhatsApp, Signal, and Telegram — 8-layer SQLite recovery, anti-forensics detection, court-ready reports.
SecurityRonin/chat4n6’s past year of commit activity - shepherd Public
One screen. Every agent. Full control. Kanban ADE for Claude Code, Codex, AdaL, OpenCode, Gemini CLI, Aider, Goose, Plandex, gptme. iTerm2 session adoption, YOLO rules engine, quality gates, one-click PRs, Alaya memory, kernel sandbox, name/logo generators, North Star PMF. 1,100+ tests.
SecurityRonin/shepherd’s past year of commit activity - srum-forensic Public
Zero-copy ESE/SRUM forensic parser — network usage, app activity, structural integrity checks. Single static Rust binary, no Windows required.
SecurityRonin/srum-forensic’s past year of commit activity - winevt-forensic Public
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
SecurityRonin/winevt-forensic’s past year of commit activity - docx-mcp Public
MCP server for reading and editing Word (.docx) documents with track changes, comments, footnotes, and structural validation
SecurityRonin/docx-mcp’s past year of commit activity - browser-forensic Public
Browser forensic library suite — parse Chrome/Firefox/Safari artifacts, detect history clearing, carve deleted records. Single static binary, no runtime deps.
SecurityRonin/browser-forensic’s past year of commit activity - blazehash Public
Forensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdeep for the modern era.
SecurityRonin/blazehash’s past year of commit activity - memory-forensic Public
Walk Linux and Windows memory dumps in Rust — processes, modules, hooks, and injected memory. No Python required.
SecurityRonin/memory-forensic’s past year of commit activity - nameback Public
Give meaningful names to recovered files (normally only got placeholder names), based on their embedded metadata and/or contents extracted using OCR
SecurityRonin/nameback’s past year of commit activity
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…