Offline Linux Forensics & Integrity Engine
-
Updated
Jun 12, 2026 - C
Offline Linux Forensics & Integrity Engine
Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
SysPeek is a blue-team recon and threat-detection toolkit for Windows. It analyzes processes and DLLs with real signature verification, hunts for LOLBin abuse, LSASS dumping, ransomware precursors, and persistence mechanisms, then correlates everything into a single MITRE ATT&CK-mapped Threat Score with JSON/CSV/HTML export.
Open-source ReFS forensics (Resilient File System v3.4-v3.14): file listing, super-timeline, USN + MLog journals, deleted-file recovery, snapshots plus a byte-level on-disk reference.
A simple Python GUI tool to view decrypted WhatsApp msgstore.db backup files for forensic analysis and personal inspection.
CyberCrew v2.0 - Offline desktop DFIR application. PyQt6 GUI wrapping 26 forensic tools with evidence chain-of-custody, SHA-256 hashing, and automated reporting.
Hex viewer and file analyzer
Template Forensics is an open-source tool designed to detect code similarity, template reuse, and potential plagiarism between two websites. By analyzing and comparing the HTML, JSX, and structural components of web templates, it determines if one web project may have originated from or copied another.
xc is an experimental terminal chain-of-custody.
xr is an experimental fast event record analyzer.
mud-df | منصة تحقيق جنائي رقمي متكاملة (17 أداة) لـ Termux و Kali Linux. للاستخدام والنشر الحر، ممنوع تعديل الكود. واجهة عربية كاملة.
Advanced digital forensics open source tool for file analysis, metadata extraction, and threat detection. Professional-grade security analysis.
MacProbe is a macOS forensic investigation platform that collects system, network, browser, and process artifacts from live Apple Silicon systems. It cross-references findings against real-time threat intelligence feeds, correlates evidence into a unified timeline, and packages everything into an AES-256-GCM encrypted evidence vault.
To associate your repository with the forensics-tool topic, visit your repo's landing page and select "manage topics."