Showing 174 open source projects for "forensic"

View related business solutions
  • MongoDB Atlas runs apps anywhere Icon
    MongoDB Atlas runs apps anywhere

    Deploy in 115+ regions with the modern database for every enterprise.

    MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
    Start Free
  • Host LLMs in Production With On-Demand GPUs Icon
    Host LLMs in Production With On-Demand GPUs

    NVIDIA L4 GPUs. 5-second cold starts. Scale to zero when idle.

    Deploy your model, get an endpoint, pay only for compute time. No GPU provisioning or infrastructure management required.
    Start Free
  • 1
    Mobile Verification Toolkit

    Mobile Verification Toolkit

    Helps with conducting forensics of mobile devices

    Mobile Verification Toolkit (MVT) is a collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices. It has been developed and released by the Amnesty International Security Lab in July 2021 in the context of the Pegasus project along with a technical forensic methodology and forensic evidence. MVT is a forensic research tool intended for technologists and investigators. ...
    Downloads: 15 This Week
    Last Update:
    See Project
  • 2
    Tailslayer

    Tailslayer

    Library for reducing tail latency in RAM reads

    ...Tailslayer emphasizes practical analysis techniques rather than theoretical exploration. Its design reflects the need to balance privacy with investigative capabilities. Overall, it provides insight into how secure systems behave under forensic scrutiny.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 3
    Live-Forensicator

    Live-Forensicator

    A suite of Tools to aid Incidence Response and Live Forensics

    ...Because live collection can alter system state, Live-Forensicator includes options to limit intrusive actions and to capture hashes, timestamps, and provenance metadata to aid later validation. The output bundles are often compatible with other forensic parsers and workflows, which helps teams move from initial triage to deep-dive forensic analysis without re-running collection tasks.
    Downloads: 5 This Week
    Last Update:
    See Project
  • 4
    Plaso

    Plaso

    Super timeline all the things

    Plaso (Plaso Langar Að Safna Öllu), or "super timeline all the things," is a Python-based engine designed for automatic creation of timelines in digital forensic investigations. It processes various log files and artifacts to generate a chronological sequence of events, aiding analysts in understanding system activities.​
    Downloads: 6 This Week
    Last Update:
    See Project
  • $300 Free Credits to Build on Google Cloud Icon
    $300 Free Credits to Build on Google Cloud

    New customers can spin up VMs, build with AI, and query data at no cost.

    Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
    Start Free
  • 5
    Sherloq

    Sherloq

    An open source digital image forensic toolset

    Sherloq is a research-oriented toolkit designed for digital image forensics, providing an integrated environment to experiment with algorithms for image analysis and tampering detection. Rather than functioning as an automated decision-making system, it serves as a companion tool for researchers, enthusiasts, and students who want to explore forensic techniques from scientific literature and workshops. The project emphasizes transparency and community collaboration, contrasting with proprietary forensic tools that often rely on secrecy. Initially developed in C++ in 2015 and later transitioned to a Qt-based GUI in 2017, Sherloq has since been ported to Python with PySide2, Matplotlib, and OpenCV to improve accessibility and ease of development. ...
    Downloads: 5 This Week
    Last Update:
    See Project
  • 6
    YellowKey

    YellowKey

    YellowKey Bitlocker Bypass Vulnerability

    ...It highlights how recovery tooling and boot-adjacent components can create serious risks even when full-disk encryption is enabled. The repository is relevant to security teams, system administrators, forensic analysts, and researchers who monitor Windows endpoint exposure. Because the topic involves bypassing encrypted storage protections, its safest use is for understanding risk, validating defensive posture in authorized environments, and prioritizing patching or mitigation. It should be treated as sensitive security research rather than a user-facing utility.
    Downloads: 259 This Week
    Last Update:
    See Project
  • 7
    Timesketch

    Timesketch

    Collaborative forensic timeline analysis

    Timesketch is a collaborative forensic timeline analysis platform used to investigate security incidents by turning diverse evidence into a single, searchable chronology. Analysts ingest logs and artifacts from many sources—endpoints, servers, cloud services—and Timesketch normalizes them into events on a unified timeline. Powerful search, aggregations, and saved views help you pivot quickly, highlight anomalies, and preserve investigative steps for later review.
    Downloads: 1 This Week
    Last Update:
    See Project
  • 8
    MemProcFS Analyzer

    MemProcFS Analyzer

    Automated Forensic Analysis of Windows Memory Dumps for DFIR

    MemProcFS-Analyzer is a forensic analysis toolset that builds on the MemProcFS virtual filesystem to make volatile memory artefacts easier to browse and interpret. By exposing process memory, kernel objects, and derived artifacts as regular files, the framework lets analysts use familiar filesystem operations and standard tools (editors, grep, diff) to explore memory snapshots.
    Downloads: 6 This Week
    Last Update:
    See Project
  • 9
    WhoDB

    WhoDB

    A lightweight next-gen data explorer

    WhoDB is a lightweight audit logging extension for PostgreSQL that helps track who accessed what data and when. It uses logical decoding and hooks into PostgreSQL internals to log query metadata, user identities, and timestamps in a separate audit schema. WhoDB is useful for compliance, security monitoring, and debugging in multi-user environments.
    Downloads: 0 This Week
    Last Update:
    See Project
  • Cut Data Warehouse Costs by 54% Icon
    Cut Data Warehouse Costs by 54%

    Easily migrate from Snowflake, Redshift, or Databricks with free tools.

    BigQuery delivers 54% lower TCO with exabyte scale and flexible pricing. Free migration tools handle the SQL translation automatically.
    Start Free
  • 10
    hollows_hunter

    hollows_hunter

    Recognizes and dumps a variety of potentially malicious implants

    ...Unlike PE-sieve’s more process-specific workflow, Hollows Hunter can select targets using broader criteria such as process IDs, process names, or creation time. This makes it useful for incident response, memory triage, and forensic investigation of suspicious Windows systems. Its purpose is defensive analysis, helping researchers extract suspicious memory artifacts for deeper review.
    Downloads: 6 This Week
    Last Update:
    See Project
  • 11
    O-Saft

    O-Saft

    O-Saft - OWASP SSL advanced forensic tool

    O-Saft is an OWASP project that offers an advanced SSL/TLS analysis tool. It provides detailed information about SSL certificates and tests SSL connections against specified cipher lists, aiding in the assessment of SSL/TLS configurations. ​
    Downloads: 0 This Week
    Last Update:
    See Project
  • 12
    claude-code-transcripts

    claude-code-transcripts

    Tools for publishing transcripts for Claude Code sessions

    ...The generated HTML includes interactive navigation and can optionally be published to GitHub Gists for sharing with collaborators or embedding in other documentation. It also supports including the raw session JSON alongside the transcript for forensic or archival purposes.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 13
    Thanos.sh

    Thanos.sh

    if you are Thanos(root), this command could delete half your files

    Thanos.sh is a small—but dangerous—tool that randomly deletes roughly half of the files on a system (hence the name). It ships as a shell script plus a PowerShell variant (Invoke-Thanos.ps1) that can target files, environment variables, registry entries, functions, aliases and certificates, and the repository warns repeatedly not to run it casually. The project includes short installation notes (for example, macOS requires gshuf from coreutils) and a README that frames the script as a “real...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 14
    HiddenVM

    HiddenVM

    HiddenVM — Use any desktop OS without leaving a trace

    If at any time Tails pushes an unexpected update, and HiddenVM is not yet updated for it, and you are stuck with a new Tails and no working HiddenVM version, you can re-download and temporarily use an earlier version of Tails until HiddenVM is updated. There are archived direct HTTP download mirrors of Tails images, archived official torrents with PGP signatures, or third-party archives at linuxtracker.org or fosstorrents.com, etc. (Always verify third-party torrents with archived official...
    Downloads: 2 This Week
    Last Update:
    See Project
  • 15

    BrokerForensicAnalyzer

    Free MT5 EA that detects broker manipulation and VDP fingerprints

    ...Key capabilities: - Measures spread widening around news events and during low-liquidity periods - Detects asymmetric slippage patterns (negative vs positive slippage ratios) - Identifies requote clustering and systematic execution delays - Generates statistical confidence scores with forensic verdict ratings - Produces regulator-ready PDF reports with full methodology documentation Version 1.00 - First Public Release (March 2026)
    Downloads: 0 This Week
    Last Update:
    See Project
  • 16

    C99 Shell

    Powerful and classic PHP web shell

    ...This tool is widely used by security professionals to understand how unauthorized scripts operate and to strengthen server defenses. Use C99 Shell responsibly in a secure environment for testing or forensic analysis only.
    Downloads: 5 This Week
    Last Update:
    See Project
  • 17
    key-elf

    key-elf

    Forensic tool to recover lost BTC private keys.

    A powerful utility to hunt down Bitcoin private keys from deleted wallet.dat files or damaged hard drives. If you accidentally deleted your Bitcoin Core wallet or formatted your disk, this tool can help. It bypasses the file system and scans the raw data directly, looking for the unique "fingerprint" (ASN.1 signature) of Bitcoin private keys to recover them from the digital wreckage.The Graphical User Interface (GUI) is the advanced/premium version. If needed, please visit:...
    Downloads: 37 This Week
    Last Update:
    See Project
  • 18
    Adaptive Intelligence

    Adaptive Intelligence

    Adaptive Intelligence also known as "Artificial General Intelligence"

    Adaptive Intelligence is the implementation of neural science, forensic psychology , behavioral science with machine-learning and artificial intelligence to provide advanced automated software platforms with the ability to adjust and thrive in dynamic environments by combining cognitive flexibility, emotional regulation, resilience, and practical problem-solving skills.
    Downloads: 8 This Week
    Last Update:
    See Project
  • 19
    recovery is a Live DVD/USB which aims troubleshooting, disk partitioning, system rescue, backup , restore data and desktop. This is a customized version of Debian Live. It contains : GParted, Clonezilla, Boot-Repair, LibreOffice and a lot of tools like ddrescue, Nwipe, TestDisk, DejaDup and many more recovery is modular in design, meaning programs can be installed simply by double clicking on module files. https://sourceforge.net/projects/recovery/files/modules/ version 2.5 - 31...
    Downloads: 66 This Week
    Last Update:
    See Project
  • 20
    REDACT

    REDACT

    Erase everything. Leave nothing.

    REDACT 4.0.0 is an open-source Windows anti-forensics & artifact sanitization suite that permanently destroys 285 system artifacts — browser history, registry traces, NTFS change journals, Windows Recall AI snapshots, live RAM, and encrypted volume key material. New in 4.0.0: Auto-Trigger Engine — 7 triggers: USB Panic, Login Failure, Dead Man's Switch, VPN Disconnect, WiFi Change, Time Window, Forensic Tool Detection. BitLocker and VeraCrypt header destruction renders encrypted volumes permanently unrecoverable. EFS key wipe and Windows Hello NGC store included. Zero-footprint: Transient Execution Splitting, NTFS File Cliff Masking, Registry LastWrite Spoofing. 8 wipe standards: 1-Pass Quick, NIST SP 800-88, HMG IS5, AFSSI-5020, NAVSO P-5239-26, VSITR, 7-Pass DoD 5220.22-M, 35-Pass Gutmann. 13 browsers: Chrome, Edge, Firefox, Brave, Vivaldi, Arc, Zen, Pale Moon, Tor & more. ...
    Downloads: 19 This Week
    Last Update:
    See Project
  • 21
    Cyrethium

    Cyrethium

    Cyrethium GNU/Linux Debian Based Privacy and Security Focused OS

    ARCHIVAL NOTICE: Cyrethium Project This project has been long discontinued and is no longer being maintained by the developer. Please note that: Status: This distribution was officially abandoned some time ago. There are no plans for future updates, security patches, or support. Liability Disclaimer: The developer accepts no responsibility for any damages, security vulnerabilities, or data loss resulting from the use of this outdated software. Use it strictly at your own...
    Leader badge
    Downloads: 19 This Week
    Last Update:
    See Project
  • 22
    Chronolabs Cooperative

    Chronolabs Cooperative

    Superior Chronologistics ~ Transmultiversity organisation at home+out!

    The Chronolabs cooperative has been operating from Sydney and around Australia from June 2006, we have and offer both closed and open source solutions to both the website consumer (Someone who needs a website) which can be either Person, Business or Government we also offer some Scientific testing and forensic systems as well as study broader topics away from web-design, the internet that are Boarder-line in this industry and beyond. Starting as a small start-up in 2006, Chronolabs has gone from strength to strength in supporting the Open Source community, namely XOOPS (see: http://xoops.org/) which was adopted by Chronolabs as a lot of the programmers from our community of developing this period was new to languages like PHP and LAMP Stack and XOOPS being OOP CI which is used in all VS and VS.NET it was the ideal choice for in-depth analysis and learning these open control mechanism coming from a Visual Studio and Visual Studio .NET
    Downloads: 4 This Week
    Last Update:
    See Project
  • 23
    Cyphernight-MAX SEC
    ...Unique features include per-chunk authentication, single-use uniqueness markers, encrypted key vaults, forced external archive loading for safe inspection of ZIP/RAR/ISO files, universal forensic archive extraction, and steganography (LSB hiding of files inside images). Additional highlights: a serverless P2P Wormhole for local network file transfer, customizable UI themes (Dark, Light, Matrix) support@dexmond.com
    Leader badge
    Downloads: 1 This Week
    Last Update:
    See Project
  • 24
    T-PHANTOM OS

    T-PHANTOM OS

    Saudi cybersecurity Linux distro for DFIR and authorized pentesting

    ...T-PHANTOM OS 5.3 provides an organized KDE Plasma environment for cybersecurity professionals, DFIR specialists, researchers, students, and system administrators. The platform supports Arabic and English and brings together practical security assessment, forensic investigation, vulnerability analysis, network-security, reverse-engineering, and system-administration workflows. Developer: Eng. Talal Fawaz Al-Sohimiy Official Website: https://talalsuhaimi.com GitHub: https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS Current Release: T-PHANTOM OS 5.3
    Downloads: 4 This Week
    Last Update:
    See Project
  • 25
    q4rescue

    q4rescue

    A live linux Rescue toolkit/Emergency OS - based on q4os Trinity

    A live linux system rescue toolkit based on q4os Trinity available as a bootable iso for administrating, repairing and cloning/restoring your system and data. Check wiki for full description : https://sourceforge.net/p/q4rescue/wiki/ Main tools: -Foxclone -Rescuezilla -Clonezilla -DDrescue-gui -qtfsarchiver -G4L -Apart -Testdisk -Photorec -Boot Repair -WoeUSB -Q4OS imager -UNetbootin -usbimager -Kdirstats -Kdiskmark -Rclone & Rclone...
    Downloads: 71 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • 3
  • 4
  • 5
  • Next