Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 26
Repositories
- mbr-partition-forensic Public
Forensic-grade MBR parser: anomaly detection, slack-space analysis, boot code fingerprinting, EBR chain traversal, and filesystem signature identification
SecurityRonin/mbr-partition-forensic’s past year of commit activity - dar-forensic Public
Forensic-grade pure-Rust reader for Denis Corbin DAR (Disk ARchiver) archives, incl. Passware Kit Mobile mobile-extraction archives; formats 1–11 with transparent gzip/bzip2/xz decompression, hardened and fuzz-tested against malicious input.
SecurityRonin/dar-forensic’s past year of commit activity - apm-partition-forensic Public
Forensic-grade Apple Partition Map (APM) reader — Driver Descriptor Map + partition entries
SecurityRonin/apm-partition-forensic’s past year of commit activity - gpt-partition-forensic Public
Forensic-grade GUID Partition Table (GPT) parser — CRC32 integrity, primary/backup reconciliation, anomaly detection
SecurityRonin/gpt-partition-forensic’s past year of commit activity - ntfs-forensic Public
Forensic-grade NTFS reader: MFT/attribute parsing, timestomping detection, alternate data streams, deleted-record carving, slack-space recovery, and adversarial-input hardening
SecurityRonin/ntfs-forensic’s past year of commit activity - vmdk-forensic Public
Pure-Rust VMware VMDK virtual-disk container library — monolithicSparse/streamOptimized/flat; published as the vmdk-core crate (imported as vmdk)
SecurityRonin/vmdk-forensic’s past year of commit activity - ewf-forensic Public
Forensic integrity analysis and repair for EWF (Expert Witness Format / E01) images
SecurityRonin/ewf-forensic’s past year of commit activity - vhdx-forensic Public
Forensic integrity analyzer for VHDX (Hyper-V) virtual disks — tamper/anomaly findings + in-memory repair, built on vhdx-core
SecurityRonin/vhdx-forensic’s past year of commit activity - qcow2-forensic Public
Pure-Rust QCOW2 forensics: reader (qcow2-core) + anomaly auditor (qcow2-forensic) — backing files, snapshots, encryption, refcount orphans on the forensicnomicon report model
SecurityRonin/qcow2-forensic’s past year of commit activity - forensicnomicon Public
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
SecurityRonin/forensicnomicon’s past year of commit activity
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…