Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 26
Repositories
- iso9660-forensic Public
Pure Rust forensic ISO 9660 reader — multi-session, UDF, Rock Ridge, Joliet, El Torito, 2352-byte raw sectors
SecurityRonin/iso9660-forensic’s past year of commit activity - vmdk Public
Pure-Rust read-only VMware VMDK reader with forensic recovery: read past a damaged grain directory via the redundant GD, plus the ddb/provenance metadata qemu-img and libvmdk discard. Read + Seek over the virtual disk.
SecurityRonin/vmdk’s past year of commit activity - dar-forensic Public
Forensic-grade pure-Rust reader for Denis Corbin DAR (Disk ARchiver) archives, incl. Passware Kit Mobile mobile-extraction archives; formats 7–11, hardened and fuzz-tested against malicious input.
SecurityRonin/dar-forensic’s past year of commit activity - forensicnomicon Public
DFIR catalog: 6,551 forensic artifacts, LOL/LOFL binaries, abusable sites — query via 4n6query CLI or Rust library
SecurityRonin/forensicnomicon’s past year of commit activity - disk-forensic Public
Forensic disk partitioning-scheme orchestrator — auto-detects MBR/GPT/APM and dispatches to the right parser
SecurityRonin/disk-forensic’s past year of commit activity - mbr-forensic Public
Forensic-grade MBR parser: anomaly detection, slack-space analysis, boot code fingerprinting, EBR chain traversal, and filesystem signature identification
SecurityRonin/mbr-forensic’s past year of commit activity - ntfs-forensic Public
Forensic-grade NTFS reader: MFT/attribute parsing, timestomping detection, alternate data streams, deleted-record carving, slack-space recovery, and adversarial-input hardening
SecurityRonin/ntfs-forensic’s past year of commit activity - apm-forensic Public
Forensic-grade Apple Partition Map (APM) reader — Driver Descriptor Map + partition entries
SecurityRonin/apm-forensic’s past year of commit activity - gpt-forensic Public
Forensic-grade GUID Partition Table (GPT) parser — CRC32 integrity, primary/backup reconciliation, anomaly detection
SecurityRonin/gpt-forensic’s past year of commit activity - hfsplus-forensic Public
Forensic-grade Apple HFS+/HFSX reader — volume header, catalog B-tree directory listing, and data-fork file extraction
SecurityRonin/hfsplus-forensic’s past year of commit activity
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…