awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

8 Repos

Awesome GitHub RepositoriesForensics Analysis

Tools for investigating artifacts, memory, and file system integrity.

Explore 8 awesome GitHub repositories matching part of an awesome list · Forensics Analysis. Refine with filters or upvote what's useful.

Awesome Forensics Analysis GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • zardus/ctf-toolsAvatar von zardus

    zardus/ctf-tools

    9,434Auf GitHub ansehen↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Ships a collection of utilities for memory forensics, XOR data decoding, and binary analysis.

    Shell
    Auf GitHub ansehen↗9,434
  • volatilityfoundation/volatilityAvatar von volatilityfoundation

    volatilityfoundation/volatility

    7,971Auf GitHub ansehen↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Framework for investigating memory dumps.

    Pythonmalwarememorypython
    Auf GitHub ansehen↗7,971
  • iagox86/dnscat2Avatar von iagox86

    iagox86/dnscat2

    3,839Auf GitHub ansehen↗

    dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe

    Hosts communication through DNS tunnels.

    PHP
    Auf GitHub ansehen↗3,839
  • rabbitstack/fibratusAvatar von rabbitstack

    rabbitstack/fibratus

    2,493Auf GitHub ansehen↗

    Adversary tradecraft detection, protection, and hunting

    Exploration and tracing tool for the Windows kernel.

    Goadversaryblueteamedr
    Auf GitHub ansehen↗2,493
  • kost/dvcs-ripperAvatar von kost

    kost/dvcs-ripper

    1,771Auf GitHub ansehen↗

    Rip web accessible (distributed) version control systems: SVN/GIT/HG...

    Rips web-accessible distributed version control systems.

    Perl
    Auf GitHub ansehen↗1,771
  • snovvcrash/usbripAvatar von snovvcrash

    snovvcrash/usbrip

    1,185Auf GitHub ansehen↗

    Tracking history of USB events on GNU/Linux

    Tracks USB device history and artifacts on Linux.

    Python
    Auf GitHub ansehen↗1,185
  • moyix/creddumpAvatar von moyix

    moyix/creddump

    286Auf GitHub ansehen↗

    Automatically exported from code.google.com/p/creddump

    Extracts credentials from Windows memory dumps.

    Python
    Auf GitHub ansehen↗286
  • williballenthin/shellbagsAvatar von williballenthin

    williballenthin/shellbags

    160Auf GitHub ansehen↗

    Cross-platform, open-source shellbag parser

    Investigates Windows shellbag artifacts.

    Python
    Auf GitHub ansehen↗160
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Forensics Analysis