Skip to content
#

windows-forensics

Here are 97 public repositories matching this topic...

Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.

  • Updated Aug 17, 2026
  • Rust

Ferramenta pericial desenvolvida para agilizar a triagem inicial e análise de evidências digitais, além de permitir a Aquisição Forense (Bit-a-bit) de unidades lógicas e físicas. Um "canivete suíço" offline e portátil que faz o trabalho pesado de extração de dados de forma rápida, segura e em lote.

  • Updated Aug 30, 2026
  • Python

DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI

  • Updated Sep 6, 2026
  • Rust

Practical labs, case studies, and investigation notes for CHFI v11 — covering digital forensics, malware forensics, incident response, evidence collection, and analysis tools.

  • Updated Aug 31, 2025

Add this topic to your repo

To associate your repository with the windows-forensics topic, visit your repo's landing page and select "manage topics."

Learn more