Skip to content
#

disk-forensics

Here are 22 public repositories matching this topic...

TRACE-Forensic-Toolkit

Open-source digital forensics (DFIR) toolkit with a desktop GUI: analyse E01, AFF4, raw/dd and VMDK disk images, recover deleted files by file carving, build timelines, search evidence and run YARA/Sigma rules. Windows, macOS, Linux.

  • Updated Oct 7, 2026
  • Python

Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.

  • Updated Aug 17, 2026
  • Rust

Practical labs, case studies, and investigation notes for CHFI v11 — covering digital forensics, malware forensics, incident response, evidence collection, and analysis tools.

  • Updated Aug 31, 2025

From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe

  • Updated Sep 21, 2026
  • Rust

🔍 Dijital Adli Bilişim (DFIR) A'dan Z'ye Türkçe kaynak. Disk, bellek, ağ, Windows, Linux, mobil ve bulut analizi. Volatility, Autopsy, Wireshark, KAPE kullanımı. Olay müdahale playbook'ları, malware analizi ve mahkeme raporu yazımı. 20 bölüm.

  • Updated Jul 3, 2026

Add this topic to your repo

To associate your repository with the disk-forensics topic, visit your repo's landing page and select "manage topics."

Learn more