15 مستودعات
Methods for investigating and analyzing digital evidence.
Explore 15 awesome GitHub repositories matching security & cryptography · Digital Forensics. Refine with filters or upvote what's useful.
This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext
Supports incident investigation through tools designed to analyze digital artifacts and system logs.
This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin
Provides access to tools and methodologies for digital forensics and incident investigation.
This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen
Provides methods for investigating and analyzing digital evidence.
John is a command-line security utility designed for password strength auditing and cryptographic hash recovery. It functions as a professional tool for identifying weak user credentials and recovering access to protected files, archives, and private keys across various operating systems, databases, and applications. The software distinguishes itself through a high-performance architecture that utilizes processor-level vector instructions to perform parallel cryptographic operations. It incorporates a rule-based mutation engine that transforms dictionary words into complex candidates based on
Analyzes password-protected evidence and encrypted containers during security investigations to extract sensitive information.
Unredacter هو أداة لرؤية الحاسوب لإعادة بناء النصوص وأداة للطب الشرعي للصور مصممة لاستعادة الأحرف المخفية من الصور المنقطة (pixelated). تعمل كأداة لعكس التنقيط لتحديد النص داخل الكتل المرئية المحجوبة. يستخدم النظام عملية مقارنة كتل الصور المنقطة مقابل أحرف مرشحة مُصيّرة تطابق الأنماط الطباعية للنص المستهدف. يسمح هذا بإعادة بناء المعلومات المحجوبة من خلال التحليل المرئي الآلي. يغطي المشروع قدرات لتحليل الطب الشرعي الرقمي، واختبار تنقيح الصور، وتقييم تسريب المعلومات للتحقق من فعالية تقنيات الإخفاء القائمة على الصور.
Analyzes redacted documents and screenshots to uncover hidden text as part of a digital forensics investigation.
Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com
Provides a comprehensive framework for examining system artifacts, network connections, and running processes during security investigations.
pyWhat is a Python-based data extraction tool designed to scan files and text for sensitive identifiers, credentials, and network artifacts using regular expressions. It functions as a pattern matching engine and PII scanner capable of identifying personal identifiers and sensitive data patterns across directories and binary files. The project specializes in the identification of unknown data formats through file signatures and the extraction of high-value identifiers, such as URLs, IP addresses, and phone numbers, from network capture files. It utilizes a rarity-based filtering system and sp
Filters and sorts identified data patterns to isolate relevant evidence and reduce false positives during investigations.
This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r
Offers signatures for investigating digital evidence, including malicious code embedded in documents and emails.
EQGRP هو إطار عمل حصان طروادة للوصول عن بُعد ومجموعة أدوات ما بعد الاستغلال. يوفر بنية تحتية مركزية للقيادة والتحكم لنشر الغرسات المستمرة وإدارة الوكلاء عن بُعد عبر أنظمة تشغيل متنوعة. يتضمن المشروع أدوات للتهرب من الطب الشرعي الرقمي، مثل تعديل سجلات النظام وطوابع وقت نظام الملفات لإزالة آثار التنفيذ. يتميز بنظام اعتراض الشبكة لالتقاط وإعادة بناء تدفقات البيانات عن طريق ربط جذر النظام، بالإضافة إلى استغلالات مصممة لتصعيد امتيازات النواة لرفع أذونات العملية إلى جذر إداري. تغطي مجموعة الأدوات مجموعة واسعة من الإمكانيات، بما في ذلك تنفيذ الكود عن بُعد، وتعبئة كود القشرة (shellcode) للتهرب من التوقيع، واستخراج وتحليل سجلات الأجهزة المحمولة وسجلات الاتصالات. كما يوفر أدوات لربط منافذ الشبكة وتصفح الأرشيفات المفكوكة.
Implements digital forensic evasion by modifying system logs and filesystem timestamps to remove traces of activity.
Volatility3 هو إطار عمل للطب الشرعي للذاكرة وأداة تحليل تستخدم لتحليل تفريغات الذاكرة المتطايرة. يستخرج الأدلة الرقمية ويعيد بناء حالة النظام في وقت التشغيل لاستعادة معلومات العمليات، وآثار الشبكة، وغيرها من الأدلة الجنائية. يعمل النظام كمحرك جنائي قائم على الإضافات (Plugins) ومحلل لرموز نظام التشغيل. يقوم بربط عناوين الذاكرة الخام بهياكل النظام المعروفة باستخدام جداول الرموز وطبقات الترجمة، ويوفر معمارية قابلة للتوسيع لإنشاء ماسحات ضوئية وعارضات مخصصة. يتضمن إطار العمل مستكشف ذاكرة عبر سطر الأوامر لاكتشاف البيانات في الوقت الفعلي وواجهة قابلة للبرمجة لأتمتة إنشاء تقارير الذاكرة. ويتعامل مع استخراج الأدلة الرقمية وحل رموز النظام من خلال عملية ترجمة عناوين قائمة على الطبقات.
Extracts digital evidence and runtime system state from volatile memory to investigate security incidents.
This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c
Includes resources for extracting and analyzing digital evidence in forensic investigations.
FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d
Provides a system for investigating and analyzing digital evidence via hidden information extraction from documents.
Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe
Provides a toolkit for analyzing memory dumps, extracting file metadata, and recovering deleted data from disk images.
Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment
Creates chronological records of system events to reconstruct the sequence of an attack for digital forensics.
Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central
Provides a centralized workspace for organizing and analyzing recovered data from multiple disk images.