Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Digital Forensics

Digital Forensics

114 projects

Showing 36 of 114 projects

inVtero.net
inVtero.netC#

A high-speed memory forensics tool for analyzing physical memory dumps to find/extract processes and hypervisors using virtual machine introspection.

#digital-forensics#integrity-assurance#secure-hash
Stars296
Forks52
Last commit2 years ago
PSHunt
PSHuntPowerShell

A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.

#digital-forensics#windows-security#security-automation
Stars292
Forks63
Last commit9 years ago
Orochi
OrochiJavaScript

A distributed web interface for collaborative memory forensics analysis using Volatility 3.

#orochi#digital-forensics#hacktoberfest
Stars273
Forks26
Last commit1 month ago
VolatilityBot
VolatilityBotPython

An automated memory analysis tool for malware samples and memory dumps that extracts executables, processes, injections, and artifacts.

#digital-forensics#malware-analysis#automation-tool
Stars268
Forks51
Last commit5 years ago
evolve
evolveJavaScript

A web-based interface for the Volatility memory forensics framework, enabling browser-based analysis of RAM dumps.

#digital-forensics#bottle-framework#ram-analysis
Stars259
Forks38
Last commit8 years ago
Fastfinder
FastfinderGo

A lightweight incident response tool for rapid suspicious file discovery during threat hunting and forensic triage.

#digital-forensics#file-analysis#cli-tool
Stars259
Forks28
Last commit6 months ago
MAGNET DumpIt
MAGNET DumpItRust

A Linux memory acquisition tool that creates ELF core dumps compatible with gdb, crash, and drgn for incident response.

#digital-forensics#debugging-tools#elf-core-dump
Stars246
Forks28
Last commit2 years ago
PyrsistenceSniper
PyrsistenceSniperPython

A Python tool for offline detection of Windows persistence mechanisms in forensic collections like KAPE dumps or mounted disk images.

#digital-forensics#kape#registry-analysis
Stars241
Forks31
Last commit3 months ago
pcapfex
pcapfexPython

A Python tool that finds and extracts files from packet capture (pcap) files for forensic analysis.

#digital-forensics#plugin-system#python-2
Stars229
Forks43
Last commit6 years ago
Hoarder
HoarderPython

A Windows artifact collection and parsing tool for targeted digital forensics and incident response investigations.

#digital-forensics#artifact-parser#disk-forensics
Stars216
Forks23
Last commit5 years ago
DAMM
DAMMPython

An open-source memory forensics tool built on Volatility for differential analysis and data reduction in malware investigations.

#digital-forensics#volatility#python
Stars215
Forks47
Last commit9 years ago
EVTXtract
EVTXtractPython

Recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.

#digital-forensics#data-recovery#python
Stars211
Forks24
Last commit1 year ago
VolDiff
VolDiffPython

A Python script that uses Volatility to analyze malware memory footprints by comparing Windows memory images before and after infection.

#digital-forensics#security-tools#malware-analysis
Stars195
Forks45
Last commit8 years ago
AChoir
AChoirC++

A scripting framework for standardizing and automating Windows live forensic artifact acquisition using common utilities.

#digital-forensics#scripting-framework#remote-acquisition
Stars192
Forks29
Last commit4 years ago
RECmd
RECmdRebol

A command-line tool for parsing, searching, and analyzing Windows Registry hives with batch processing and forensic capabilities.

#digital-forensics#batch-processing#registry-analysis
Stars179
Forks43
Last commit2 months ago
FastIR Collector Linux
FastIR Collector LinuxPython

A live forensics tool for Linux that collects system artifacts and logs them to CSV files for compromise detection.

#digital-forensics#csv-output#python2
Stars177
Forks45
Last commit5 years ago
Invoke-LiveResponse
Invoke-LiveResponsePowerShell

A PowerShell-based live response and forensic collection tool for targeted incident response on Windows systems.

#forensic-collection#digital-forensics#liveresponse
Stars152
Forks29
Last commit4 years ago
CIRTKit
CIRTKitPython

A unified console for digital forensics and incident response built on the Viper Framework.

#digital-forensics#viper-framework#security-automation
Stars152
Forks23
Last commit9 years ago
CIRTkit
CIRTkitPython

A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.

#digital-forensics#viper-framework#dfir
Stars152
Forks23
Last commit9 years ago
Malwarehouse
MalwarehousePython

A command-line utility for storing, tagging, and searching malware samples to help analysts manage their workflow.

#digital-forensics#sample-management#command-line-tool
Stars137
Forks40
Last commit8 months ago
Acquire
AcquirePython

A tool to quickly gather forensic artifacts from disk images or live systems into lightweight containers for digital forensic triage.

#digital-forensics#disk-imaging#python
Stars123
Forks40
Last commit2 months ago
itunes_backup2hashcat
itunes_backup2hashcatPerl

Extracts data from iTunes backup Manifest.plist files to generate hashes compatible with hashcat cracking modes 14700 and 14800.

#digital-forensics#itunes-backup#ios-forensics
Stars119
Forks42
Last commit
nsrllookup
nsrllookupC++

A command-line tool for digital forensics that checks file MD5 hashes against the NSRL Reference Data Set to identify known software files.

#digital-forensics#md5#nsrl
Stars116
Forks12
Last commit5 years ago
Digital Forensics Artifact Knowledge Base
Digital Forensics Artifact Knowledge BasePython

A knowledge base documenting digital forensics artifacts to help investigators understand evidence sources and their forensic significance.

#digital-forensics#evidence-collection#forensic-artifacts
Stars90
Forks15
Last commit
WINHELLO2hashcat
WINHELLO2hashcatPython

Extracts Windows Hello PIN hashes for offline cracking with Hashcat.

#digital-forensics#python-tool#windows-security
Stars86
Forks7
Last commit4 years ago
SFlock
SFlockPython

A Python utility for securely unpacking and staging suspicious files, designed for integration with malware analysis tools like Cuckoo Sandbox.

#digital-forensics#sandbox-integration#cuckoo-sandbox
Stars85
Forks56
Last commit2 years ago
MaltegoVT
MaltegoVTPython

A set of Maltego transforms for VirusTotal Public API v2.0 with daily query caching to speed up resolutions.

#digital-forensics#osint#security-analysis
Stars82
Forks21
Last commit10 years ago
FSquaDRA
FSquaDRAJava

A tool for fast detection of repackaged Android applications by comparing resource file digests from APK signatures.

#digital-forensics#batch-processing#jaccard-similarity
Stars75
Forks25
Last commit3 years ago
Mem
MemC

A forensic tool for dumping memory from Android devices requiring root access.

#digital-forensics#process-analysis#android-forensics
Stars72
Forks10
Last commit11 years ago
ELF-Packer
ELF-PackerPython

A polymorphic runtime cryptor that XOR-encrypts the .text section of x86_64 ELF binaries on Linux, changing the hash on each execution.

#digital-forensics#runtime-encryption#polymorphic-code
Stars59
Forks11
Last commit
Muninn
MuninnPython

A memory forensics helper that automates initial data extraction from Windows memory images using Volatility.

#digital-forensics#volatility#python
Stars52
Forks9
Last commit8 years ago
python-evt
python-evtPython

A pure Python parser for classic Windows Event Log (.evt) files, enabling forensic analysis and log extraction.

#digital-forensics#evt-format#python-library
Stars52
Forks14
Last commit3 years ago
TotalRecall
TotalRecallPython

A Volatility-based script for memory forensics that runs plugins, creates timelines, and scans for malware using YARA, ClamAV, and VirusTotal.

#digital-forensics#virustotal#clamav
Stars49
Forks7
Last commit9 years ago
SPECTR3
SPECTR3C#

A forensic tool for remote acquisition, triage, and analysis of block devices via iSCSI protocol.

#digital-forensics#portable-tool#acquisition
Stars44
Forks5
Last commit1 year ago
Panorama
PanoramaPython

A Windows incident response tool that generates comprehensive system reports without requiring admin permissions.

#digital-forensics#file-discovery#network-scanning
Stars41
Forks8
Last commit9 years ago
Java IDX Parser
Java IDX ParserPython

A forensic tool that parses Java Cache IDX files to extract malware download history and binary data for incident response.

#digital-forensics#python-tool#idx-parser
Stars40
Forks10
Last commit8 years ago
PreviousPage 3 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
9 years ago
2 months ago
8 years ago
Next
#Incident Response83
#Security Tools32
#Cybersecurity31
#Malware Analysis30
#Python29
#Dfir26
#Forensics22
#Threat Hunting17
#Memory Forensics16
#Windows Forensics15
#Threat Intelligence15
#Forensic Analysis12