awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 repositorios

Awesome GitHub RepositoriesDigital Forensics

Methods for investigating and analyzing digital evidence.

Explore 15 awesome GitHub repositories matching security & cryptography · Digital Forensics. Refine with filters or upvote what's useful.

Awesome Digital Forensics GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • z4nzu/hackingtoolAvatar de Z4nzu

    Z4nzu/hackingtool

    77,515Ver en GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Supports incident investigation through tools designed to analyze digital artifacts and system logs.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    Ver en GitHub↗77,515
  • carpedm20/awesome-hackingAvatar de carpedm20

    carpedm20/awesome-hacking

    15,722Ver en GitHub↗

    This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

    Provides access to tools and methodologies for digital forensics and incident investigation.

    awesomehacking
    Ver en GitHub↗15,722
  • sbilly/awesome-securityAvatar de sbilly

    sbilly/awesome-security

    14,022Ver en GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    Provides methods for investigating and analyzing digital evidence.

    awesome-listsecurity
    Ver en GitHub↗14,022
  • openwall/johnAvatar de openwall

    openwall/john

    13,268Ver en GitHub↗

    John is a command-line security utility designed for password strength auditing and cryptographic hash recovery. It functions as a professional tool for identifying weak user credentials and recovering access to protected files, archives, and private keys across various operating systems, databases, and applications. The software distinguishes itself through a high-performance architecture that utilizes processor-level vector instructions to perform parallel cryptographic operations. It incorporates a rule-based mutation engine that transforms dictionary words into complex candidates based on

    Analyzes password-protected evidence and encrypted containers during security investigations to extract sensitive information.

    Cassemblerccracker
    Ver en GitHub↗13,268
  • bishopfox/unredacterAvatar de BishopFox

    BishopFox/unredacter

    8,351Ver en GitHub↗

    Unredacter es un reconstructor de texto por visión artificial y utilidad de análisis forense de imágenes diseñado para recuperar caracteres ocultos de imágenes pixeladas. Funciona como una herramienta para revertir la pixelación e identificar texto dentro de bloques visuales oscurecidos. El sistema utiliza un proceso de comparación de bloques de imagen pixelados contra caracteres candidatos renderizados que coinciden con los estilos tipográficos del texto objetivo. Esto permite la reconstrucción de información oscurecida mediante análisis visual automatizado. El proyecto cubre capacidades para el análisis forense digital, pruebas de redacción de imágenes y evaluación de fugas de información para verificar la efectividad de las técnicas de enmascaramiento basadas en imágenes.

    Analyzes redacted documents and screenshots to uncover hidden text as part of a digital forensics investigation.

    TypeScript
    Ver en GitHub↗8,351
  • volatilityfoundation/volatilityAvatar de volatilityfoundation

    volatilityfoundation/volatility

    7,971Ver en GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Provides a comprehensive framework for examining system artifacts, network connections, and running processes during security investigations.

    Pythonmalwarememorypython
    Ver en GitHub↗7,971
  • bee-san/pywhatAvatar de bee-san

    bee-san/pyWhat

    7,150Ver en GitHub↗

    pyWhat is a Python-based data extraction tool designed to scan files and text for sensitive identifiers, credentials, and network artifacts using regular expressions. It functions as a pattern matching engine and PII scanner capable of identifying personal identifiers and sensitive data patterns across directories and binary files. The project specializes in the identification of unknown data formats through file signatures and the extraction of high-value identifiers, such as URLs, IP addresses, and phone numbers, from network capture files. It utilizes a rarity-based filtering system and sp

    Filters and sorts identified data patterns to isolate relevant evidence and reduce false positives during investigations.

    Pythoncybercybersecurityhacking
    Ver en GitHub↗7,150
  • yara-rules/rulesAvatar de Yara-Rules

    Yara-Rules/rules

    4,712Ver en GitHub↗

    This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r

    Offers signatures for investigating digital evidence, including malicious code embedded in documents and emails.

    YARA
    Ver en GitHub↗4,712
  • x0rz/eqgrpAvatar de x0rz

    x0rz/EQGRP

    4,201Ver en GitHub↗

    EQGRP es un framework de troyano de acceso remoto y kit de herramientas de post-explotación. Proporciona una infraestructura centralizada de comando y control para desplegar implantes persistentes y gestionar agentes remotos en diversos sistemas operativos. El proyecto incluye herramientas para la evasión forense digital, como la modificación de registros del sistema y marcas de tiempo del sistema de archivos para eliminar rastros de ejecución. Cuenta con un sistema de interceptación de red para capturar y reconstruir flujos de datos mediante hooks en el root del sistema, así como exploits diseñados para la escalada de privilegios del kernel para elevar los permisos de proceso a root administrativo. El kit de herramientas cubre una amplia gama de capacidades, incluyendo ejecución remota de código, empaquetado de shellcode para evasión de firmas, y la exfiltración y análisis de registros de dispositivos móviles y registros de telecomunicaciones. También proporciona utilidades para enlazar puertos de red y navegar por archivos descifrados.

    Implements digital forensic evasion by modifying system logs and filesystem timestamps to remove traces of activity.

    Perl
    Ver en GitHub↗4,201
  • volatilityfoundation/volatility3Avatar de volatilityfoundation

    volatilityfoundation/volatility3

    4,192Ver en GitHub↗

    Volatility3 es un framework de análisis forense de memoria y herramienta utilizada para analizar volcados de memoria volátil. Extrae artefactos digitales y reconstruye el estado de ejecución de un sistema para recuperar información de procesos, artefactos de red y otras pruebas forenses. El sistema funciona como un motor forense basado en plugins y un resolvedor de símbolos del sistema operativo. Mapea direcciones de memoria sin procesar a estructuras de sistema conocidas utilizando tablas de símbolos y capas de traducción, y proporciona una arquitectura extensible para crear escáneres y renderizadores personalizados. El framework incluye un explorador de memoria de línea de comandos para el descubrimiento de datos en tiempo real y una interfaz programable para automatizar la generación de informes de memoria. Maneja la extracción de artefactos digitales y la resolución de símbolos del sistema a través de un proceso de traducción de direcciones basado en capas.

    Extracts digital evidence and runtime system state from volatile memory to investigate security incidents.

    Python
    Ver en GitHub↗4,192
  • jekil/awesome-hackingAvatar de jekil

    jekil/awesome-hacking

    3,746Ver en GitHub↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Includes resources for extracting and analyzing digital evidence in forensic investigations.

    Pythoncurated-listforensicshacking
    Ver en GitHub↗3,746
  • elevenpaths/focaAvatar de ElevenPaths

    ElevenPaths/FOCA

    3,434Ver en GitHub↗

    FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d

    Provides a system for investigating and analyzing digital evidence via hidden information extraction from documents.

    C#
    Ver en GitHub↗3,434
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Ver en GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a toolkit for analyzing memory dumps, extracting file metadata, and recovering deleted data from disk images.

    Shellhackhackinghacking-tool
    Ver en GitHub↗3,020
  • yamato-security/hayabusaAvatar de Yamato-Security

    Yamato-Security/hayabusa

    3,027Ver en GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Creates chronological records of system events to reconstruct the sequence of an attack for digital forensics.

    Rustattackcybersecuritydetection
    Ver en GitHub↗3,027
  • sleuthkit/autopsyAvatar de sleuthkit

    sleuthkit/autopsy

    3,015Ver en GitHub↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Provides a centralized workspace for organizing and analyzing recovered data from multiple disk images.

    Javaforensicsjava
    Ver en GitHub↗3,015
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Digital Forensics

Explorar subetiquetas

  • Anti-ForensicsTechniques and tools used to manipulate or delete digital evidence to evade forensic analysis. **Distinct from Digital Forensics:** Distinct from Digital Forensics: focuses on the evasion and removal of evidence rather than its investigation.
  • Forensic Workspace ManagementOrganizing and analyzing recovered data from multiple sources within a structured forensic workspace. **Distinct from Digital Forensics:** Distinct from Digital Forensics by focusing on the organization and management of evidence within a workspace.