awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to forensicartifacts/artifacts

Open-source alternatives to Artifacts

30 open-source projects similar to forensicartifacts/artifacts, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Artifacts alternative.

  • tclahr/uacAvatar de tclahr

    tclahr/uac

    1,241Voir sur GitHub↗
    Shellaixcollectorcomputer-forensics
    Voir sur GitHub↗1,241
  • orlikoski/cylrAvatar de orlikoski

    orlikoski/CyLR

    727Voir sur GitHub↗

    CyLR - Live Response Collection Tool

    C#
    Voir sur GitHub↗727
  • velocidex/velociraptorAvatar de Velocidex

    Velocidex/velociraptor

    3,769Voir sur GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    Voir sur GitHub↗3,769
  • diogo-fernan/ir-rescueAvatar de diogo-fernan

    diogo-fernan/ir-rescue

    489Voir sur GitHub↗

    A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

    Batchfile
    Voir sur GitHub↗489
  • markbaggett/werejugoM

    MarkBaggett/werejugo

    0Voir sur GitHub↗

    Version 0.9 - beta

    Voir sur GitHub↗0

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • yamato-security/welaAvatar de Yamato-Security

    Yamato-Security/WELA

    102Voir sur GitHub↗

    WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR), providing visibility into system activity and security events.

    PowerShell
    Voir sur GitHub↗102
  • wagga40/zircoliteAvatar de wagga40

    wagga40/Zircolite

    782Voir sur GitHub↗
    Pythonauditddetectionevtx
    Voir sur GitHub↗782
  • google/timesketchAvatar de google

    google/timesketch

    3,355Voir sur GitHub↗

    Collaborative forensic timeline analysis

    Python
    Voir sur GitHub↗3,355
  • log2timeline/plasoAvatar de log2timeline

    log2timeline/plaso

    2,095Voir sur GitHub↗

    Super timeline all the things

    Python
    Voir sur GitHub↗2,095
  • jpcertcc/logontracerAvatar de JPCERTCC

    JPCERTCC/LogonTracer

    3,136Voir sur GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    Voir sur GitHub↗3,136
  • microsoft/avmlAvatar de microsoft

    microsoft/avml

    1,098Voir sur GitHub↗

    AVML - Acquire Volatile Memory for Linux

    Rust
    Voir sur GitHub↗1,098
  • philhagen/sof-elkAvatar de philhagen

    philhagen/sof-elk

    1,740Voir sur GitHub↗

    This repository contains the configuration and support files for the SOF-ELK® VM Appliance.

    Ruby
    Voir sur GitHub↗1,740
  • thewhiteninja/ntfstoolAvatar de thewhiteninja

    thewhiteninja/ntfstool

    617Voir sur GitHub↗

    Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

    C++
    Voir sur GitHub↗617
  • yamato-security/hayabusaAvatar de Yamato-Security

    Yamato-Security/hayabusa

    3,027Voir sur GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Rustattackcybersecuritydetection
    Voir sur GitHub↗3,027
  • fox-it/acquireAvatar de fox-it

    fox-it/acquire

    121Voir sur GitHub↗

    acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.

    Python
    Voir sur GitHub↗121
  • google/grrAvatar de google

    google/grr

    5,074Voir sur GitHub↗

    GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro

    Python
    Voir sur GitHub↗5,074
  • dfirkuiper/kuiperAvatar de DFIRKuiper

    DFIRKuiper/Kuiper

    893Voir sur GitHub↗

    Digital Forensics Investigation Platform

    JavaScript
    Voir sur GitHub↗893
  • forensicanalysis/artifactcollectorAvatar de forensicanalysis

    forensicanalysis/artifactcollector

    308Voir sur GitHub↗

    🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system

    Go
    Voir sur GitHub↗308
  • ahmedkhlief/apt-hunterAvatar de ahmedkhlief

    ahmedkhlief/APT-Hunter

    1,408Voir sur GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    Voir sur GitHub↗1,408
  • google/rekallAvatar de google

    google/rekall

    1,998Voir sur GitHub↗

    Rekall Memory Forensic Framework

    Python
    Voir sur GitHub↗1,998
  • google/turbiniaAvatar de google

    google/turbinia

    783Voir sur GitHub↗
    Pythonclouddfirforensics
    Voir sur GitHub↗783
  • invoke-ir/powerforensicsAvatar de Invoke-IR

    Invoke-IR/PowerForensics

    1,435Voir sur GitHub↗

    PowerForensics provides an all in one platform for live disk forensic analysis

    C#
    Voir sur GitHub↗1,435
  • bsi-bund/rdpcachestitcherAvatar de BSI-Bund

    BSI-Bund/RdpCacheStitcher

    329Voir sur GitHub↗

    RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps. Using raw RDP cache tile bitmaps extracted by tools like e.g. ANSSI's BMC-Tools (https://github.com/ANSSI-FR/bmc-tools) as input, it provides a graphical user interface and…

    C++
    Voir sur GitHub↗329
  • markbaggett/srum-dumpM

    MarkBaggett/srum-dump

    0Voir sur GitHub↗

    SRUM-DUMP extracts data from the System Resource Utilization Management (SRUM) database and generates an Excel spreadsheet. This tool is invaluable for forensic investigations, as SRUM maintains records of applications that have run on a system within the last 30 days.

    Voir sur GitHub↗0
  • threatresponse/margaritashotgunAvatar de ThreatResponse

    ThreatResponse/margaritashotgun

    253Voir sur GitHub↗

    Remote Memory Acquisition Tool

    Python
    Voir sur GitHub↗253
  • rough007/cdqrAvatar de rough007

    rough007/CDQR

    345Voir sur GitHub↗

    The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted drives and extracted artifacts from Windows, Linux, MacOS, and Android devices

    Python
    Voir sur GitHub↗345
  • sleuthkit/autopsyAvatar de sleuthkit

    sleuthkit/autopsy

    3,015Voir sur GitHub↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Javaforensicsjava
    Voir sur GitHub↗3,015
  • elevenpaths/focaAvatar de ElevenPaths

    ElevenPaths/FOCA

    3,434Voir sur GitHub↗

    FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d

    C#
    Voir sur GitHub↗3,434
  • bromiley/olafB

    bromiley/olaf

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • andrewrathbun/dfirmindmapsAvatar de AndrewRathbun

    AndrewRathbun/DFIRMindMaps

    549Voir sur GitHub↗

    This is a repository to centralize DFIR-related Mind Maps created with any Mind Mapping suites. The main point of this repo is to not only provide the Mind Maps for various DFIR Tools & Artifacts, but provide the source of the Mind Maps so others can use, improve, or modify how they see fit for…

    Voir sur GitHub↗549