Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Digital Forensics

Digital Forensics

114 projects

Showing 36 of 114 projects

Awesome Security Newsletters
Awesome Security Newsletters

A curated collection of periodic cybersecurity newsletters covering news, research, tools, vulnerabilities, and threat analysis.

#digital-forensics#vulnerability-management#newsletter
Stars1.3k
Forks99
Last commit18 days ago
Noriben
NoribenPython

A portable Python script that automates malware analysis by collecting runtime indicators using Sysinternals Procmon.

#digital-forensics#sysinternals-procmon#sandbox
Stars1.3k
Forks227
Last commit4 months ago
Forensic Artifact repository
Forensic Artifact repositoryPython

A community-sourced, machine-readable knowledge base of digital forensic artifacts for use in forensic tools and investigations.

#digital-forensics#yaml#machine-readable
Stars1.3k
Forks224
Last commit2 months ago
Firmwalker
FirmwalkerShell

A bash script for searching extracted firmware file systems to identify security issues, sensitive data, and interesting artifacts.

#digital-forensics#embedded-systems#bash-script
Stars1.2k
Forks193
Last commit2 years ago
Android Malware Github repo
Android Malware Github repoShell

The largest open collection of Android malware samples for security research and analysis.

#digital-forensics#malware-samples#cybersecurity-research
Stars1.2k
Forks381
Last commit6 months ago
USBRip
USBRipPython

A command-line forensics tool for tracking USB device connection history on GNU/Linux systems.

#digital-forensics#command-line-tool#usb-events
Stars1.2k
Forks113
Last commit3 years ago
Dissect
Dissect

A digital forensics and incident response framework for unified analysis of forensic artifacts across disk formats, filesystems, and operating systems.

#digital-forensics#filesystem-parsing#modular-framework
Stars1.1k
Forks85
Last commit4 months ago
AVML
AVMLRust

A portable volatile memory acquisition tool for Linux that captures memory images without requiring target OS or kernel knowledge.

#rust-tool#digital-forensics#lime-compatible
Stars1.1k
Forks92
Last commit3 days ago
Aurora Incident Response
Aurora Incident ResponseJavaScript

A desktop application for incident responders to track findings, tasks, and visualize timelines during cybersecurity investigations.

#digital-forensics#desktop-application#incident-response-tooling
Stars1.1k
Forks130
Last commit
macOS Artifact Parsing Tool (mac_apt)
macOS Artifact Parsing Tool (mac_apt)Python

A Python-based DFIR framework for extracting forensic artifacts from macOS and iOS disk images or live systems.

#apfs-parser#digital-forensics#macos-forensics
Stars1.1k
Forks126
Last commit1 day ago
Awesome Anti Forensics
Awesome Anti ForensicsHTML

A curated list of tools and resources for anti-forensic activities, including data hiding, encryption, steganography, and evidence removal.

#digital-forensics#privacy-tools#penetration-testing
Stars1.0k
Forks106
Last commit
Kuiper
KuiperJavaScript

A digital forensics investigation platform for parsing, searching, visualizing evidence, and enabling team collaboration.

#digital-forensics#timeline-visualization#artifacts
Stars897
Forks119
Last commit1 year ago
OSX Security Awesome
OSX Security Awesome

A curated collection of macOS and iOS security resources including tools, research, malware analysis, and hardening guides.

#system-hardening#digital-forensics#hacking-mac
Stars786
Forks114
Last commit27 days ago
CyLR
CyLRC#

A cross-platform forensic artifact collection tool for NTFS file systems that minimizes host impact.

#digital-forensics#forensic-analysis#dotnet-core
Stars732
Forks96
Last commit4 years ago
CapTipper
CapTipperPython

A Python tool to analyze, explore, and revive malicious HTTP traffic from PCAP files for security research.

#digital-forensics#python-tool#network-forensics
Stars724
Forks160
Last commit3 years ago
RegRipper
RegRipperPerl

A Windows Registry forensics tool for extracting and analyzing data from registry hives using Perl-based plugins.

#digital-forensics#registry-analysis#security-analysis
Stars712
Forks151
Last commit1 month ago
Awesome Event IDs
Awesome Event IDs

A curated collection of Event ID resources for digital forensics and incident response professionals.

#evtx-analysis#digital-forensics#digitalforensics
Stars661
Forks89
Last commit2 years ago
nightHawk
nightHawkGo

An asynchronous forensic data presentation framework for incident response, built on Elasticsearch.

#digital-forensics#go-application#redline-integration
Stars608
Forks123
Last commit6 years ago
docker-explorer
docker-explorerPython

A forensic tool for exploring offline Docker container filesystems and metadata from disk images.

#digital-forensics#python-tool#container-security
Stars556
Forks44
Last commit1 year ago
docker-explorer
docker-explorerPython

A forensic tool for exploring offline Docker filesystems to analyze compromised containers.

#digital-forensics#python-tool#container-security
Stars556
Forks44
Last commit1 year ago
DFIRTrack
DFIRTrackPython

A system-focused web application for tracking systems, tasks, and artifacts during major digital forensics and incident response (DFIR) investigations.

#digital-forensics#incident-response-tooling#security-tooling
Stars537
Forks87
Last commit
Catalyst
CatalystVue

A self-hosted incident response platform that automates alert handling and ticket management for security teams.

#digital-forensics#ticket-system#soar
Stars536
Forks73
Last commit6 days ago
friTap
friTapPython

A tool for real-time SSL/TLS key extraction and traffic decryption to simplify encrypted network analysis for security researchers.

#digital-forensics#android-https-capture#pcap
Stars528
Forks48
Last commit17 days ago
FastIR Collector
FastIR CollectorPython

Collects Windows forensic artifacts to detect early system compromises through analysis of live data.

#digital-forensics#python-tool#csv-output
Stars520
Forks129
Last commit5 years ago
CCF-VM
CCF-VMShell

An open-source platform for collecting, processing, and analyzing forensic artifacts from macOS, Windows, and Linux systems.

#digital-forensics#dfir#forensic-analysis
Stars514
Forks81
Last commit3 years ago
MalConfScan
MalConfScanPython

A Volatility plugin that extracts configuration data and decoded strings from known malware families in memory images.

#digital-forensics#memory#security
Stars498
Forks69
Last commit2 years ago
PSRecon
PSReconPowerShell

A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.

#digital-forensics#windows-security#security-automation
Stars496
Forks106
Last commit9 years ago
ir-rescue
ir-rescueBatchfile

A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.

#batch-script#digital-forensics#sysinternals
Stars489
Forks92
Last commit5 years ago
Meerkat
MeerkatPowerShell

A PowerShell module collection for agentless artifact gathering and reconnaissance on Windows endpoints.

#digital-forensics#threat#baseline
Stars483
Forks85
Last commit1 year ago
Bitscout
BitscoutShell

A customizable live OS constructor tool written in Bash for remote forensics, malware hunting, and incident response.

#digital-forensics#bootable-media#remote-forensics
Stars480
Forks109
Last commit1 year ago
VolUtility
VolUtilityPython

A web interface for the Volatility memory forensics framework that runs plugins, stores results in MongoDB, and enables cross-plugin search.

#digital-forensics#yara-rules#security-analysis
Stars387
Forks80
Last commit6 months ago
DFTimewolf
DFTimewolfPython

A framework for orchestrating forensic collection, processing, and data export through modular recipes.

#digital-forensics#workflow-automation#open-source-forensics
Stars351
Forks79
Last commit7 days ago
Cold Disk Quick Response
Cold Disk Quick ResponsePython

A forensic artifact parsing tool that quickly analyzes disk images and extracted artifacts from Windows, Linux, macOS, and Android devices.

#digital-forensics#android-forensics#disk-image-analysis
Stars345
Forks51
Last commit
MFT Browser
MFT BrowserPowerShell

A Windows GUI tool that reconstructs directory trees and analyzes FILE records from NTFS Master File Table ($MFT) files.

#mft-parser#digital-forensics#disk-image-analysis
Stars330
Forks34
Last commit1 year ago
artifactcollector
artifactcollectorGo

A customizable single-binary agent for collecting forensic artifacts from Windows, macOS, and Linux systems.

#forensicartifacts#digital-forensics#macos-forensics
Stars309
Forks25
Last commit1 year ago
PowerShell implementation of Autoruns
PowerShell implementation of AutorunsPowerShell

A PowerShell module for live incident response that enumerates Windows autorun artifacts to detect persistence mechanisms used by malware and legitimate programs.

#digital-forensics#malware-detection#persistence-enumeration
Stars301
Forks52
Last commit
PreviousPage 2 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
2 years ago
2 years ago
6 months ago
4 years ago
5 days ago
Next
#Incident Response83
#Security Tools32
#Cybersecurity31
#Malware Analysis30
#Python29
#Dfir26
#Forensics22
#Threat Hunting17
#Memory Forensics16
#Windows Forensics15
#Threat Intelligence15
#Forensic Analysis12