awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

8 dépôts

Awesome GitHub RepositoriesForensics Analysis

Tools for investigating artifacts, memory, and file system integrity.

Explore 8 awesome GitHub repositories matching part of an awesome list · Forensics Analysis. Refine with filters or upvote what's useful.

Awesome Forensics Analysis GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • zardus/ctf-toolsAvatar de zardus

    zardus/ctf-tools

    9,434Voir sur GitHub↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Ships a collection of utilities for memory forensics, XOR data decoding, and binary analysis.

    Shell
    Voir sur GitHub↗9,434
  • volatilityfoundation/volatilityAvatar de volatilityfoundation

    volatilityfoundation/volatility

    7,971Voir sur GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Framework for investigating memory dumps.

    Pythonmalwarememorypython
    Voir sur GitHub↗7,971
  • iagox86/dnscat2Avatar de iagox86

    iagox86/dnscat2

    3,839Voir sur GitHub↗

    dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe

    Hosts communication through DNS tunnels.

    PHP
    Voir sur GitHub↗3,839
  • rabbitstack/fibratusAvatar de rabbitstack

    rabbitstack/fibratus

    2,493Voir sur GitHub↗

    Adversary tradecraft detection, protection, and hunting

    Exploration and tracing tool for the Windows kernel.

    Goadversaryblueteamedr
    Voir sur GitHub↗2,493
  • kost/dvcs-ripperAvatar de kost

    kost/dvcs-ripper

    1,771Voir sur GitHub↗

    Rip web accessible (distributed) version control systems: SVN/GIT/HG...

    Rips web-accessible distributed version control systems.

    Perl
    Voir sur GitHub↗1,771
  • snovvcrash/usbripAvatar de snovvcrash

    snovvcrash/usbrip

    1,185Voir sur GitHub↗

    Tracking history of USB events on GNU/Linux

    Tracks USB device history and artifacts on Linux.

    Python
    Voir sur GitHub↗1,185
  • moyix/creddumpAvatar de moyix

    moyix/creddump

    286Voir sur GitHub↗

    Automatically exported from code.google.com/p/creddump

    Extracts credentials from Windows memory dumps.

    Python
    Voir sur GitHub↗286
  • williballenthin/shellbagsAvatar de williballenthin

    williballenthin/shellbags

    160Voir sur GitHub↗

    Cross-platform, open-source shellbag parser

    Investigates Windows shellbag artifacts.

    Python
    Voir sur GitHub↗160
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Forensics Analysis