awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 个仓库

Awesome GitHub RepositoriesDigital Forensics

Methods for investigating and analyzing digital evidence.

Explore 15 awesome GitHub repositories matching security & cryptography · Digital Forensics. Refine with filters or upvote what's useful.

Awesome Digital Forensics GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • z4nzu/hackingtoolZ4nzu 的头像

    Z4nzu/hackingtool

    77,515在 GitHub 上查看↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Supports incident investigation through tools designed to analyze digital artifacts and system logs.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    在 GitHub 上查看↗77,515
  • carpedm20/awesome-hackingcarpedm20 的头像

    carpedm20/awesome-hacking

    15,722在 GitHub 上查看↗

    This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

    Provides access to tools and methodologies for digital forensics and incident investigation.

    awesomehacking
    在 GitHub 上查看↗15,722
  • sbilly/awesome-securitysbilly 的头像

    sbilly/awesome-security

    14,022在 GitHub 上查看↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    Provides methods for investigating and analyzing digital evidence.

    awesome-listsecurity
    在 GitHub 上查看↗14,022
  • openwall/johnopenwall 的头像

    openwall/john

    13,268在 GitHub 上查看↗

    John is a command-line security utility designed for password strength auditing and cryptographic hash recovery. It functions as a professional tool for identifying weak user credentials and recovering access to protected files, archives, and private keys across various operating systems, databases, and applications. The software distinguishes itself through a high-performance architecture that utilizes processor-level vector instructions to perform parallel cryptographic operations. It incorporates a rule-based mutation engine that transforms dictionary words into complex candidates based on

    Analyzes password-protected evidence and encrypted containers during security investigations to extract sensitive information.

    Cassemblerccracker
    在 GitHub 上查看↗13,268
  • bishopfox/unredacterBishopFox 的头像

    BishopFox/unredacter

    8,351在 GitHub 上查看↗

    Unredacter 是一个计算机视觉文本重建器和图像取证工具,旨在从像素化图像中恢复隐藏字符。它充当一种反转像素化以识别模糊视觉块内文本的工具。 该系统使用将像素化图像块与匹配目标文本排版样式的渲染候选字符进行比较的过程。这允许通过自动化视觉分析来重建模糊信息。 该项目涵盖了数字取证分析、图像脱敏测试和信息泄露评估的功能,以验证基于图像的掩码技术的有效性。

    Analyzes redacted documents and screenshots to uncover hidden text as part of a digital forensics investigation.

    TypeScript
    在 GitHub 上查看↗8,351
  • volatilityfoundation/volatilityvolatilityfoundation 的头像

    volatilityfoundation/volatility

    7,971在 GitHub 上查看↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Provides a comprehensive framework for examining system artifacts, network connections, and running processes during security investigations.

    Pythonmalwarememorypython
    在 GitHub 上查看↗7,971
  • bee-san/pywhatbee-san 的头像

    bee-san/pyWhat

    7,150在 GitHub 上查看↗

    pyWhat is a Python-based data extraction tool designed to scan files and text for sensitive identifiers, credentials, and network artifacts using regular expressions. It functions as a pattern matching engine and PII scanner capable of identifying personal identifiers and sensitive data patterns across directories and binary files. The project specializes in the identification of unknown data formats through file signatures and the extraction of high-value identifiers, such as URLs, IP addresses, and phone numbers, from network capture files. It utilizes a rarity-based filtering system and sp

    Filters and sorts identified data patterns to isolate relevant evidence and reduce false positives during investigations.

    Pythoncybercybersecurityhacking
    在 GitHub 上查看↗7,150
  • yara-rules/rulesYara-Rules 的头像

    Yara-Rules/rules

    4,712在 GitHub 上查看↗

    This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r

    Offers signatures for investigating digital evidence, including malicious code embedded in documents and emails.

    YARA
    在 GitHub 上查看↗4,712
  • x0rz/eqgrpx0rz 的头像

    x0rz/EQGRP

    4,201在 GitHub 上查看↗

    EQGRP 是一个远程访问木马框架和后渗透工具包。它提供了一个集中式命令与控制基础设施,用于部署持久化植入物并管理跨不同操作系统的远程智能体。 该项目包括用于数字取证规避的工具,例如修改系统日志和文件系统时间戳以删除执行痕迹。它具有一个网络拦截系统,用于通过挂钩系统根目录来捕获和重构数据流,以及专为内核权限提升而设计的漏洞利用,以将进程权限提升为管理根权限。 该工具包涵盖了广泛的功能,包括远程代码执行、用于签名规避的 Shellcode 打包,以及移动设备日志和电信记录的渗出与解析。它还提供用于绑定网络端口和浏览解密归档的工具。

    Implements digital forensic evasion by modifying system logs and filesystem timestamps to remove traces of activity.

    Perl
    在 GitHub 上查看↗4,201
  • volatilityfoundation/volatility3volatilityfoundation 的头像

    volatilityfoundation/volatility3

    4,192在 GitHub 上查看↗

    Volatility3 是一个内存取证框架和分析工具,用于解析易失性内存转储。它提取数字工件并重构系统的运行时状态,以恢复进程信息、网络工件和其他取证证据。 该系统作为一个基于插件的取证引擎和操作系统符号解析器运行。它使用符号表和转换层将原始内存地址映射到已知的系统结构,并为创建自定义扫描器和渲染器提供了可扩展的架构。 该框架包含一个用于实时数据发现的命令行内存浏览器,以及一个用于自动化生成内存报告的编程接口。它通过基于层的地址转换过程处理数字工件提取和系统符号解析。

    Extracts digital evidence and runtime system state from volatile memory to investigate security incidents.

    Python
    在 GitHub 上查看↗4,192
  • jekil/awesome-hackingjekil 的头像

    jekil/awesome-hacking

    3,746在 GitHub 上查看↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Includes resources for extracting and analyzing digital evidence in forensic investigations.

    Pythoncurated-listforensicshacking
    在 GitHub 上查看↗3,746
  • elevenpaths/focaElevenPaths 的头像

    ElevenPaths/FOCA

    3,434在 GitHub 上查看↗

    FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d

    Provides a system for investigating and analyzing digital evidence via hidden information extraction from documents.

    C#
    在 GitHub 上查看↗3,434
  • jaykali/maskphishjaykali 的头像

    jaykali/maskphish

    3,020在 GitHub 上查看↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a toolkit for analyzing memory dumps, extracting file metadata, and recovering deleted data from disk images.

    Shellhackhackinghacking-tool
    在 GitHub 上查看↗3,020
  • yamato-security/hayabusaYamato-Security 的头像

    Yamato-Security/hayabusa

    3,027在 GitHub 上查看↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Creates chronological records of system events to reconstruct the sequence of an attack for digital forensics.

    Rustattackcybersecuritydetection
    在 GitHub 上查看↗3,027
  • sleuthkit/autopsysleuthkit 的头像

    sleuthkit/autopsy

    3,015在 GitHub 上查看↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Provides a centralized workspace for organizing and analyzing recovered data from multiple disk images.

    Javaforensicsjava
    在 GitHub 上查看↗3,015
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Digital Forensics

探索子标签

  • Anti-ForensicsTechniques and tools used to manipulate or delete digital evidence to evade forensic analysis. **Distinct from Digital Forensics:** Distinct from Digital Forensics: focuses on the evasion and removal of evidence rather than its investigation.
  • Forensic Workspace ManagementOrganizing and analyzing recovered data from multiple sources within a structured forensic workspace. **Distinct from Digital Forensics:** Distinct from Digital Forensics by focusing on the organization and management of evidence within a workspace.