Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 26
Repositories
- dar-forensic Public
Forensic-grade pure-Rust reader for Denis Corbin DAR (Disk ARchiver) archives, incl. Passware Kit Mobile mobile-extraction archives; formats 1–11 with transparent gzip/bzip2/xz decompression, hardened and fuzz-tested against malicious input.
SecurityRonin/dar-forensic’s past year of commit activity - vmdk-forensic Public
Pure-Rust VMware VMDK virtual-disk container library — monolithicSparse/streamOptimized/flat; published as the vmdk-core crate (imported as vmdk)
SecurityRonin/vmdk-forensic’s past year of commit activity - vhdx-forensic Public
Forensic integrity analyzer for VHDX (Hyper-V) virtual disks — tamper/anomaly findings + in-memory repair, built on vhdx-core
SecurityRonin/vhdx-forensic’s past year of commit activity - ntfs-forensic Public
Forensic-grade NTFS reader: MFT/attribute parsing, timestomping detection, alternate data streams, deleted-record carving, slack-space recovery, and adversarial-input hardening
SecurityRonin/ntfs-forensic’s past year of commit activity - usnjrnl-forensic Public
The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomping detection, USN carving, and more.
SecurityRonin/usnjrnl-forensic’s past year of commit activity - vhdx-core Public archive
Pure-Rust VHDX (Hyper-V) virtual-disk container library — reader (writer planned), published as the vhdx-core crate
SecurityRonin/vhdx-core’s past year of commit activity - ewf-forensic Public
Forensic integrity analysis and repair for EWF (Expert Witness Format / E01) images
SecurityRonin/ewf-forensic’s past year of commit activity - lzo Public
GPL-free, safe, no_std pure-Rust LZO1X decompressor — decode lzo1x_1 / lzo1x_999 streams (lzop, kernel/initramfs, btrfs, liblzo2) with zero C, zero dependencies, and #![forbid(unsafe_code)]; validated against liblzo2 and fuzz-hardened against malicious input.
SecurityRonin/lzo’s past year of commit activity - forensicnomicon Public
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
SecurityRonin/forensicnomicon’s past year of commit activity - disk-forensic Public
Forensic disk-image orchestrator — decodes E01/VMDK/VHDX/VHD/QCOW2/DMG containers, auto-detects MBR/GPT/APM, and routes ISO 9660 to filesystem analysis
SecurityRonin/disk-forensic’s past year of commit activity
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…