awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

75 Repos

Awesome GitHub RepositoriesDigital Forensics

Frameworks for memory analysis and incident response data collection.

Explore 75 awesome GitHub repositories matching part of an awesome list · Digital Forensics. Refine with filters or upvote what's useful.

Awesome Digital Forensics GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • nationalsecurityagency/ghidraAvatar von NationalSecurityAgency

    NationalSecurityAgency/ghidra

    69,740Auf GitHub ansehen↗

    Ghidra is a software reverse engineering suite designed to analyze compiled binaries and reconstruct program logic without access to original source code. It provides an interactive environment for disassembly and decompilation, utilizing a platform-independent intermediate representation to maintain consistency across diverse hardware architectures. The framework supports automated binary analysis through programmatic routines, enabling the investigation of complex code patterns and security indicators. The platform distinguishes itself through a modular architecture that allows for extensiv

    Open-source suite for reverse engineering and malware analysis.

    Javadisassemblerreverse-engineeringsoftware-analysis
    Auf GitHub ansehen↗69,740
  • burntsushi/ripgrepAvatar von BurntSushi

    BurntSushi/ripgrep

    65,112Auf GitHub ansehen↗

    ripgrep is a command-line utility designed for searching through large file trees and source code repositories. It functions as a recursive text processor that traverses directories to locate and display matching patterns, serving as a high-performance alternative to traditional search tools. The tool distinguishes itself through a focus on execution speed and intelligent file handling. It utilizes a finite automata-based regular expression engine to ensure linear time complexity and employs hardware-level acceleration for literal byte sequence scanning. By integrating with version control sy

    Fast command-line tool for searching text patterns.

    Rustclicommand-linecommand-line-tool
    Auf GitHub ansehen↗65,112
  • soxoj/maigretAvatar von soxoj

    soxoj/maigret

    33,154Auf GitHub ansehen↗

    Maigret is an open-source intelligence framework designed for automated digital footprint discovery and identity investigation. It functions as a search engine that aggregates profile metadata by querying thousands of websites for specific usernames, mapping an individual's online presence across diverse platforms. The tool distinguishes itself through recursive discovery capabilities, which identify links within discovered profiles to expand the scope of an investigation automatically. It supports cross-platform identity correlation by mapping disparate accounts and pseudonymous personas, in

    Tool for gathering information on individuals via usernames.

    Pythonblueteamclicybersecurity
    Auf GitHub ansehen↗33,154
  • osquery/osqueryAvatar von osquery

    osquery/osquery

    23,113Auf GitHub ansehen↗

    Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu

    Tool for querying system state using SQL-like syntax.

    C++hacktoberfestintrusion-detectionmonitoring
    Auf GitHub ansehen↗23,113
  • mandiant/flare-vmAvatar von mandiant

    mandiant/flare-vm

    8,799Auf GitHub ansehen↗

    Flare-VM ist eine Windows-Umgebung zur Malware-Analyse, die aus Installationsskripten besteht, welche die Bereitstellung einer virtuellen Maschine automatisieren. Sie bietet eine umfassende Suite an Reverse-Engineering-Werkzeugen, einschließlich Decompiler und Debugger, zusammen mit den notwendigen Systemkonfigurationen und Umgebungsvariablen für die Sicherheitsforschung. Das Projekt fungiert als Orchestrator für Images virtueller Maschinen und ermöglicht die automatisierte Erstellung, Verwaltung und den Export spezialisierter Analyse-Appliances. Es bietet eine konfigurationsgesteuerte Werkzeugauswahl und die Möglichkeit, die Installationslogik durch benutzerdefinierte Registry-Modifikationen und Systemlayout-Definitionen zu erweitern. Das System umfasst Funktionen für eine isolierte Netzwerkkonfiguration, um die externe Kommunikation über den Host-Only-Modus zu verhindern. Es verwaltet zudem den gesamten Lebenszyklus von Analyseständen durch Snapshot-basiertes Zustandsmanagement, einschließlich der Möglichkeit, Snapshots als verifizierte Appliance-Dateien zu bereinigen oder zu exportieren.

    Windows-based security distribution for malware analysis.

    PowerShell
    Auf GitHub ansehen↗8,799
  • volatilityfoundation/volatilityAvatar von volatilityfoundation

    volatilityfoundation/volatility

    7,971Auf GitHub ansehen↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Framework for memory extraction and analysis.

    Pythonmalwarememorypython
    Auf GitHub ansehen↗7,971
  • mandiant/capaAvatar von mandiant

    mandiant/capa

    6,062Auf GitHub ansehen↗

    capa is a binary capability scanner that identifies high-level behaviors and actions an executable can perform, such as network communication or file manipulation. It functions as a malware behavior analysis tool and a MITRE ATT&CK mapping framework, scanning PE, ELF, .NET, and shellcode files through both static analysis and dynamic sandbox report processing. The tool distinguishes itself through a YAML-based detection rule engine that defines detection logic in human-readable files, with conditions expressed as feature combinations and logical operators. It integrates with IDA Pro, Ghidra,

    Tool for identifying capabilities in executable files.

    Python
    Auf GitHub ansehen↗6,062
  • google/grrAvatar von google

    google/grr

    5,074Auf GitHub ansehen↗

    GRR ist eine verteilte Incident-Response-Plattform und ein Orchestrator für asynchrone forensische Aufgaben. Es fungiert als Remote-Forensik-Framework, das entwickelt wurde, um flüchtige Daten, Systemspeicher und digitale Artefakte von Remote-Hosts während der Reaktion auf Sicherheitsvorfälle zu sammeln und zu analysieren. Das System arbeitet als Remote-Endpoint-Triage-System und nutzt eine koordinierte Architektur zur Verwaltung einer Flotte von Agenten. Es ermöglicht die Ausführung investigativer Aufgaben über mehrere Systeme hinweg und erlaubt die Suche nach Dateien und Registrierungseinträgen über eine große Flotte von Maschinen, um kompromittierte Hosts zu identifizieren. Die Plattform bietet Funktionen für die digitale forensische Analyse, einschließlich der Fähigkeit, Rohdateisysteme zu analysieren und chronologische Systemereignis-Zeitlinien zu generieren. Sie enthält zudem Tools für das Flotten-Monitoring im Unternehmen, um die Ressourcennutzung zu verfolgen und wiederkehrende forensische Aufgaben zu planen.

    Framework for remote live forensics and incident response.

    Python
    Auf GitHub ansehen↗5,074
  • volatilityfoundation/volatility3Avatar von volatilityfoundation

    volatilityfoundation/volatility3

    4,192Auf GitHub ansehen↗

    Volatility3 ist ein Framework für Speicherforensik und ein Analysetool, das zum Parsen von flüchtigen Speicher-Dumps verwendet wird. Es extrahiert digitale Artefakte und rekonstruiert den Laufzeitzustand eines Systems, um Prozessinformationen, Netzwerk-Artefakte und andere forensische Beweise wiederherzustellen. Das System fungiert als Plugin-basiertes forensisches Engine und als Symbol-Resolver für Betriebssysteme. Es bildet rohe Speicheradressen auf bekannte Systemstrukturen unter Verwendung von Symboltabellen und Übersetzungsschichten ab und bietet eine erweiterbare Architektur für die Erstellung benutzerdefinierter Scanner und Renderer. Das Framework enthält einen Kommandozeilen-Speicherexplorer für die Echtzeit-Datenerkennung und eine programmierbare Schnittstelle zur Automatisierung der Erstellung von Speicherberichten. Es handhabt die Extraktion digitaler Artefakte und die Auflösung von System-Symbolen durch einen schichtbasierten Adressübersetzungsprozess.

    Advanced framework for memory forensics and analysis.

    Python
    Auf GitHub ansehen↗4,192
  • ufrisk/memprocfsAvatar von ufrisk

    ufrisk/MemProcFS

    4,202Auf GitHub ansehen↗

    MemProcFS ist ein Tool zur Analyse volatiler Speicher und ein plattformübergreifendes Speicherakquisitionssystem. Es fungiert als virtuelles Dateisystem für Speicherforensik, das physischen Speicher und Kernel-Objekte in eine virtuelle Verzeichnisstruktur mappt, die es Benutzern ermöglicht, Systemartefakte mit Standard-Dateisystem-Tools zu analysieren. Das Projekt zeichnet sich dadurch aus, dass es ein virtuelles Dateisystem für Speicherforensik bereitstellt, das das Durchsuchen und Abfragen von physischem Speicher als schreibgeschützte Dateien und Ordner ermöglicht. Es integriert zudem einen Yara-basierten Speicher-Scanner, um Malware-Signaturen und injizierten Code innerhalb des physischen Speichers zu identifizieren. Die Engine deckt ein breites Spektrum forensischer Funktionen ab, einschließlich Prozess- und Thread-Inspektion, Auflistung von Netzwerkverbindungen und Windows-Registry-Analyse. Sie unterstützt die Datenaufnahme von Live-Systemen, Crash-Dumps und virtuellen Maschinen, während sie Symbolauflösung bietet, um rohe Speicheradressen in aussagekräftige Namen zu übersetzen. Die Integration wird durch ein mehrsprachiges programmatisches Interface und native Library-Wrapper für C und Java sowie Headless-Python-Scripting für automatisierte Workflows unterstützt.

    Tool for accessing physical memory as a virtual file system.

    C
    Auf GitHub ansehen↗4,202
  • a0rtega/pafishAvatar von a0rtega

    a0rtega/pafish

    3,920Auf GitHub ansehen↗

    Pafish ist ein Anti-Analyse-Sandbox-Detektor und ein Test-Tool für Virtualisierungsumgebungen. Es dient als diagnostisches Dienstprogramm, um zu identifizieren, ob ein System innerhalb einer virtuellen Maschine oder einer Malware-Analyse-Sandbox ausgeführt wird, indem gängige Anti-Analyse-Techniken angewendet werden. Das Tool validiert die Wirksamkeit verschiedener Evasionsmethoden und unterstützt die Forschung zur Sandbox-Erkennung. Es testet, ob ein Zielsystem als virtualisierte Umgebung erkannt werden kann, um die Tarnung von Malware-Analyseumgebungen zu verbessern. Die Erkennung erfolgt durch eine Vielzahl von Verhaltensprüfungen, einschließlich Hardware-Artefaktanalyse, MAC-Adressfilterung und Registry-Key-Fingerprinting. Die Suite verwendet zudem instruktionsbasierte Erkennung, zeitbasierte Ausführungsanalyse und prozessbasiertes Umgebungs-Scanning, um Indikatoren für Virtualisierung zu identifizieren.

    Testing tool to detect virtualized malware analysis environments.

    C
    Auf GitHub ansehen↗3,920
  • velocidex/velociraptorAvatar von Velocidex

    Velocidex/velociraptor

    3,769Auf GitHub ansehen↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Endpoint visibility and digital forensic response platform.

    Godigital-forensicsendpoint-discoveryendpoint-protection
    Auf GitHub ansehen↗3,769
  • hasherezade/pe-sieveAvatar von hasherezade

    hasherezade/pe-sieve

    3,559Auf GitHub ansehen↗

    pe-sieve is a set of diagnostic tools for scanning Windows process memory to identify malicious implants, shellcode, and hooks. It functions as an in-memory implant detector, malware unpacker, and process callstack analyzer designed to locate and dump memory patches and injected code from running processes. The project identifies advanced evasion techniques, such as process hollowing and reflective injection, by verifying portable executable structures in memory. It distinguishes itself by analyzing process callstacks to detect anomalies and redirections and by reconstructing executable heade

    Tool for detecting and dumping malicious code in memory.

    C++anti-malwarehookinglibpeconv
    Auf GitHub ansehen↗3,559
  • gtworek/psbitsAvatar von gtworek

    gtworek/PSBits

    3,512Auf GitHub ansehen↗

    Simple (relatively) solutions allowing you to dig a bit deeper than usual.

    PowerShell snippets for forensic and administrative tasks.

    C
    Auf GitHub ansehen↗3,512
  • withsecurelabs/chainsawAvatar von WithSecureLabs

    WithSecureLabs/chainsaw

    3,446Auf GitHub ansehen↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Tool for rapid searching and hunting in Windows event logs.

    Rustattackblueteamchainsaw
    Auf GitHub ansehen↗3,446
  • google/timesketchAvatar von google

    google/timesketch

    3,355Auf GitHub ansehen↗

    Collaborative forensic timeline analysis

    Collaborative platform for forensic timeline analysis.

    Python
    Auf GitHub ansehen↗3,355
  • guidobartoli/sherloqAvatar von GuidoBartoli

    GuidoBartoli/sherloq

    3,150Auf GitHub ansehen↗

    An open-source digital image forensic toolset

    Open-source toolset for digital image forensics.

    Perl
    Auf GitHub ansehen↗3,150
  • sleuthkit/sleuthkitAvatar von sleuthkit

    sleuthkit/sleuthkit

    3,093Auf GitHub ansehen↗

    The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

    Core library and tools for disk forensics.

    C
    Auf GitHub ansehen↗3,093
  • jpcertcc/logontracerAvatar von JPCERTCC

    JPCERTCC/LogonTracer

    3,136Auf GitHub ansehen↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Tool for visualizing and analyzing Windows logon events.

    Pythonactive-directoryblueteamdfir
    Auf GitHub ansehen↗3,136
  • yamato-security/hayabusaAvatar von Yamato-Security

    Yamato-Security/hayabusa

    3,027Auf GitHub ansehen↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Fast Windows event log analysis tool for threat hunting.

    Rustattackcybersecuritydetection
    Auf GitHub ansehen↗3,027
Vorherige123…4Nächste
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Digital Forensics