awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 Repos

Awesome GitHub RepositoriesDigital Forensics

Methods for investigating and analyzing digital evidence.

Explore 15 awesome GitHub repositories matching security & cryptography · Digital Forensics. Refine with filters or upvote what's useful.

Awesome Digital Forensics GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • z4nzu/hackingtoolAvatar von Z4nzu

    Z4nzu/hackingtool

    77,515Auf GitHub ansehen↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Supports incident investigation through tools designed to analyze digital artifacts and system logs.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    Auf GitHub ansehen↗77,515
  • carpedm20/awesome-hackingAvatar von carpedm20

    carpedm20/awesome-hacking

    15,722Auf GitHub ansehen↗

    This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

    Provides access to tools and methodologies for digital forensics and incident investigation.

    awesomehacking
    Auf GitHub ansehen↗15,722
  • sbilly/awesome-securityAvatar von sbilly

    sbilly/awesome-security

    14,022Auf GitHub ansehen↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    Provides methods for investigating and analyzing digital evidence.

    awesome-listsecurity
    Auf GitHub ansehen↗14,022
  • openwall/johnAvatar von openwall

    openwall/john

    13,268Auf GitHub ansehen↗

    John is a command-line security utility designed for password strength auditing and cryptographic hash recovery. It functions as a professional tool for identifying weak user credentials and recovering access to protected files, archives, and private keys across various operating systems, databases, and applications. The software distinguishes itself through a high-performance architecture that utilizes processor-level vector instructions to perform parallel cryptographic operations. It incorporates a rule-based mutation engine that transforms dictionary words into complex candidates based on

    Analyzes password-protected evidence and encrypted containers during security investigations to extract sensitive information.

    Cassemblerccracker
    Auf GitHub ansehen↗13,268
  • bishopfox/unredacterAvatar von BishopFox

    BishopFox/unredacter

    8,351Auf GitHub ansehen↗

    Unredacter ist ein Computer-Vision-Tool zur Textrekonstruktion und Bildforensik, das darauf ausgelegt ist, versteckte Zeichen aus verpixelten Bildern wiederherzustellen. Es fungiert als Werkzeug zur Umkehrung der Verpixelung, um Text innerhalb verdeckter visueller Blöcke zu identifizieren. Das System verwendet einen Prozess, bei dem verpixelte Bildblöcke mit gerenderten Kandidatenzeichen verglichen werden, die den typografischen Stilen des Zieltextes entsprechen. Dies ermöglicht die Rekonstruktion verdeckter Informationen durch automatisierte visuelle Analyse. Das Projekt deckt Funktionen für digitale forensische Analysen, Tests zur Bildschwärzung und Bewertungen von Informationslecks ab, um die Wirksamkeit bildbasierter Maskierungstechniken zu überprüfen.

    Analyzes redacted documents and screenshots to uncover hidden text as part of a digital forensics investigation.

    TypeScript
    Auf GitHub ansehen↗8,351
  • volatilityfoundation/volatilityAvatar von volatilityfoundation

    volatilityfoundation/volatility

    7,971Auf GitHub ansehen↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Provides a comprehensive framework for examining system artifacts, network connections, and running processes during security investigations.

    Pythonmalwarememorypython
    Auf GitHub ansehen↗7,971
  • bee-san/pywhatAvatar von bee-san

    bee-san/pyWhat

    7,150Auf GitHub ansehen↗

    pyWhat is a Python-based data extraction tool designed to scan files and text for sensitive identifiers, credentials, and network artifacts using regular expressions. It functions as a pattern matching engine and PII scanner capable of identifying personal identifiers and sensitive data patterns across directories and binary files. The project specializes in the identification of unknown data formats through file signatures and the extraction of high-value identifiers, such as URLs, IP addresses, and phone numbers, from network capture files. It utilizes a rarity-based filtering system and sp

    Filters and sorts identified data patterns to isolate relevant evidence and reduce false positives during investigations.

    Pythoncybercybersecurityhacking
    Auf GitHub ansehen↗7,150
  • yara-rules/rulesAvatar von Yara-Rules

    Yara-Rules/rules

    4,712Auf GitHub ansehen↗

    This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r

    Offers signatures for investigating digital evidence, including malicious code embedded in documents and emails.

    YARA
    Auf GitHub ansehen↗4,712
  • x0rz/eqgrpAvatar von x0rz

    x0rz/EQGRP

    4,201Auf GitHub ansehen↗

    EQGRP ist ein Remote-Access-Trojan-Framework und Post-Exploitation-Toolkit. Es bietet eine zentrale Command-and-Control-Infrastruktur für das Deployment persistenter Implants und die Verwaltung von Remote-Agenten über diverse Betriebssysteme hinweg. Das Projekt enthält Tools für digitale forensische Evasion, wie das Modifizieren von System-Logs und Dateisystem-Zeitstempeln, um Ausführungsspuren zu entfernen. Es bietet ein Netzwerk-Interzeptionssystem zum Abfangen und Rekonstruieren von Datenströmen durch Hooking in das System-Root sowie Exploits, die für Kernel-Privilege-Escalation entwickelt wurden, um Prozessberechtigungen auf administrative Root-Ebene zu heben. Das Toolkit deckt ein breites Spektrum an Funktionen ab, einschließlich Remote-Code-Execution, Shellcode-Packing für Signatur-Evasion sowie die Exfiltration und das Parsen von Mobilgerät-Logs und Telekommunikationsaufzeichnungen. Es bietet zudem Utilities für das Binden von Netzwerkports und das Durchsuchen entschlüsselter Archive.

    Implements digital forensic evasion by modifying system logs and filesystem timestamps to remove traces of activity.

    Perl
    Auf GitHub ansehen↗4,201
  • volatilityfoundation/volatility3Avatar von volatilityfoundation

    volatilityfoundation/volatility3

    4,192Auf GitHub ansehen↗

    Volatility3 ist ein Framework für Speicherforensik und ein Analysetool, das zum Parsen von flüchtigen Speicher-Dumps verwendet wird. Es extrahiert digitale Artefakte und rekonstruiert den Laufzeitzustand eines Systems, um Prozessinformationen, Netzwerk-Artefakte und andere forensische Beweise wiederherzustellen. Das System fungiert als Plugin-basiertes forensisches Engine und als Symbol-Resolver für Betriebssysteme. Es bildet rohe Speicheradressen auf bekannte Systemstrukturen unter Verwendung von Symboltabellen und Übersetzungsschichten ab und bietet eine erweiterbare Architektur für die Erstellung benutzerdefinierter Scanner und Renderer. Das Framework enthält einen Kommandozeilen-Speicherexplorer für die Echtzeit-Datenerkennung und eine programmierbare Schnittstelle zur Automatisierung der Erstellung von Speicherberichten. Es handhabt die Extraktion digitaler Artefakte und die Auflösung von System-Symbolen durch einen schichtbasierten Adressübersetzungsprozess.

    Extracts digital evidence and runtime system state from volatile memory to investigate security incidents.

    Python
    Auf GitHub ansehen↗4,192
  • jekil/awesome-hackingAvatar von jekil

    jekil/awesome-hacking

    3,746Auf GitHub ansehen↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Includes resources for extracting and analyzing digital evidence in forensic investigations.

    Pythoncurated-listforensicshacking
    Auf GitHub ansehen↗3,746
  • elevenpaths/focaAvatar von ElevenPaths

    ElevenPaths/FOCA

    3,434Auf GitHub ansehen↗

    FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d

    Provides a system for investigating and analyzing digital evidence via hidden information extraction from documents.

    C#
    Auf GitHub ansehen↗3,434
  • jaykali/maskphishAvatar von jaykali

    jaykali/maskphish

    3,020Auf GitHub ansehen↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a toolkit for analyzing memory dumps, extracting file metadata, and recovering deleted data from disk images.

    Shellhackhackinghacking-tool
    Auf GitHub ansehen↗3,020
  • yamato-security/hayabusaAvatar von Yamato-Security

    Yamato-Security/hayabusa

    3,027Auf GitHub ansehen↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Creates chronological records of system events to reconstruct the sequence of an attack for digital forensics.

    Rustattackcybersecuritydetection
    Auf GitHub ansehen↗3,027
  • sleuthkit/autopsyAvatar von sleuthkit

    sleuthkit/autopsy

    3,015Auf GitHub ansehen↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Provides a centralized workspace for organizing and analyzing recovered data from multiple disk images.

    Javaforensicsjava
    Auf GitHub ansehen↗3,015
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Digital Forensics

Unter-Tags erkunden

  • Anti-ForensicsTechniques and tools used to manipulate or delete digital evidence to evade forensic analysis. **Distinct from Digital Forensics:** Distinct from Digital Forensics: focuses on the evasion and removal of evidence rather than its investigation.
  • Forensic Workspace ManagementOrganizing and analyzing recovered data from multiple sources within a structured forensic workspace. **Distinct from Digital Forensics:** Distinct from Digital Forensics by focusing on the organization and management of evidence within a workspace.