Skip to main content
buildradar
Sign in
Topic · forensics

forensics

Tracked open-source repos tagged forensics, sorted by stars.

59 repos
  • mac_apt@ydkhatri

    macOS (& ios) Artifact Parsing Tool

    1,081+3Star change over the last 7 days
  • hackdroid@thehackingsage

    Security Apps for Android

    1,074+1Star change over the last 7 days
  • A curated list of tools officially presented at Black Hat events

    980+8Star change over the last 7 days
  • OSINT-BIBLE@frangelbarrera

    Comprehensive 2026 OSINT guide — 450+ tools, AI intelligence, methodologies & ethics across 35 sections for investigation & threat intel.

    901+15Star change over the last 7 days
  • horus@6abd

    An OSINT / digital forensics tool built in Python

    873+41Star change over the last 7 days
  • Zircolite@wagga40

    A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

    850+2Star change over the last 7 days
  • ctf-super-hub@asdfgh1445

    面向小白用户的 CTF / 逆向 Skills 整合包:自动分流、头脑风暴、教学模式、比赛模式、只提示模式

    800+11Star change over the last 7 days
  • turbinia@google

    Automation and Scaling of Digital Forensics Tools

    793+0Star change over the last 7 days
  • PWF@bluecapesecurity

    Practical Windows Forensics Training

    783+0Star change over the last 7 days
  • python-evtx@williballenthin

    Pure Python parser for Windows Event Log files (.evtx)

    779+0Star change over the last 7 days
  • TheBigBrother@chadi0x

    The Big Brother V6.0 is a weaponized OSINT platform featuring username enumeration (473+ platforms), quad-vector visual intelligence, Sky Radar tracking, crypto wallet analysis, SSL intelligence, digital footprint reconstruction, EXIF extraction, advanced dorking, and network reconnaissance.

    758+8Star change over the last 7 days
  • operative framework is a rust investigation OSINT framework, you can interact with multiple targets, execute multiple modules, create links with target, export rapport to PDF file, add note to target or results, interact with RESTFul API, write your own modules.

    749-1Star change over the last 7 days
  • SIEM@TonyPhipps

    SIEM Tactics, Techiques, and Procedures

    730+0Star change over the last 7 days
  • EnableWindowsLogSettings@Yamato-Security

    Documentation and scripts to properly enable Windows event logs.

    718+0Star change over the last 7 days
  • forensictools@cristianzsh

    Collection of forensic tools

    704+1Star change over the last 7 days
  • Tools OSINT MOBILE

    703+3Star change over the last 7 days
  • Collection of Event ID ressources useful for Digital Forensics and Incident Response

    663+1Star change over the last 7 days
  • Live-Forensicator@Johnng007

    Cross-platform incident response and live forensics toolkit with built-in detection, structured analysis, and report generation — designed for fast, actionable security investigations.

    632+1Star change over the last 7 days
  • diffy@Netflix-Skunkworks

    :no_entry: (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.

    629+0Star change over the last 7 days
  • RecuperaBit@Lazza

    A tool for forensic file system reconstruction.

    622+0Star change over the last 7 days
  • Ominis-OSINT@AnonCatalyst

    This Python application is an OSINT (Open Source Intelligence) tool called "Ominis OSINT - Web Hunter." It performs online information gathering by querying Google for search results related to a user-inputted query. The tool extracts relevant information such as titles, URLs, and potential mentions of the query in the results.

    615+3Star change over the last 7 days
  • StegoForge@Nour833

    The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run 11 advanced detection engines to uncover hidden payloads.

    584+3Star change over the last 7 days
  • tailpipe@turbot

    select * from logs; Tailpipe is an open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, right from your terminal.

    580+0Star change over the last 7 days
  • A curated list of awesome Memory Forensics for DFIR

    563+0Star change over the last 7 days
  • SeqBox@MarcoPon

    A single file container/archive that can be reconstructed even after total loss of file system structures

    555+0Star change over the last 7 days
  • sift@teamdfir

    SIFT

    551+0Star change over the last 7 days
  • A list of 350+ free TryHackMe rooms💻 to kick off your cybersecurity learning, organized by topics for easy exploration and practical skill-building !💀💥

    548+7Star change over the last 7 days
  • ADTimeline@ANSSI-FR

    Timeline of Active Directory changes with replication metadata

    535+0Star change over the last 7 days
  • analyzeMFT@rowingdude

    analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

    533+0Star change over the last 7 days
← Back to topics