Forensics Open Source Projects
Browse 217 Forensics open source projects, ranked by GitHub stars. Find the most popular Forensics tools and libraries.
WerWolv/ImHex
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
Metrics details
| Stars | 54,230 |
radareorg/radare2
UNIX-like reverse engineering framework and command-line toolset
Metrics details
| Stars | 24,390 |
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Metrics details
| Stars | 14,317 |
mvt-project/mvt
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
Metrics details
| Stars | 12,751 |
kubeshark/kubeshark
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
Metrics details
| Stars | 12,007 |
apsdehal/awesome-ctf
A curated list of CTF frameworks, libraries, resources and softwares
Metrics details
| Stars | 11,682 |
meirwah/awesome-incident-response
A curated list of tools for incident response
Metrics details
| Stars | 9,272 |
rmusser01/Infosec_Reference
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
Metrics details
| Stars | 5,978 |
cugu/awesome-forensics
⭐️ A curated list of awesome forensic analysis tools and resources
Metrics details
| Stars | 5,135 |
google/grr
GRR Rapid Response: remote live forensics for incident response
Metrics details
| Stars | 5,083 |
Hack-with-Github/Free-Security-eBooks
Free Security and Hacking eBooks
Metrics details
| Stars | 4,948 |
volatilityfoundation/volatility3
Volatility 3.0 development
Metrics details
| Stars | 4,254 |
toolswatch/blackhat-arsenal-tools
Official Black Hat Arsenal Security Tools Repository
Metrics details
| Stars | 4,232 |
jekil/awesome-hacking
Awesome hacking is an awesome collection of hacking tools.
Metrics details
| Stars | 3,894 |
WithSecureLabs/chainsaw
Rapidly Search and Hunt through Windows Forensic Artefacts
Metrics details
| Stars | 3,603 |
decalage2/oletools
oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
Metrics details
| Stars | 3,382 |
google/timesketch
Collaborative forensic timeline analysis
Metrics details
| Stars | 3,380 |
Yamato-Security/hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Metrics details
| Stars | 3,261 |
sleuthkit/autopsy
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
Metrics details
| Stars | 3,259 |
sleuthkit/sleuthkit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
Metrics details
| Stars | 3,116 |
mikeroyal/Digital-Forensics-Guide
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
Metrics details
| Stars | 2,960 |
JohnHammond/ctf-katana
This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.
Metrics details
| Stars | 2,919 |
frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty
Metrics details
| Stars | 2,877 |
danieldurnea/FBI-tools
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Metrics details
| Stars | 2,573 |
mesquidar/ForensicsTools
A list of free and open forensics analysis tools and other resources
Metrics details
| Stars | 2,508 |
dreddsa5dies/goHackTools
Hacker tools on Go (Golang)
Metrics details
| Stars | 2,186 |
log2timeline/plaso
Super timeline all the things
Metrics details
| Stars | 2,119 |
stuxnet999/MemLabs
Educational, CTF-styled labs for individuals interested in Memory Forensics
Metrics details
| Stars | 1,880 |
m14r41/PentestingEverything
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
Metrics details
| Stars | 1,878 |
Srinivas11789/PcapXray
:snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction
Metrics details
| Stars | 1,870 |
PabloLec/RecoverPy
Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal
Metrics details
| Stars | 1,778 |
simsong/tcpflow
TCP/IP packet demultiplexer. Download from:
Metrics details
| Stars | 1,773 |
den4uk/andriller
📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.
Metrics details
| Stars | 1,586 |
obsidianforensics/hindsight
Web browser forensics for Google Chrome/Chromium
Metrics details
| Stars | 1,469 |
cisagov/Sparrow
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.
Metrics details
| Stars | 1,430 |
tclahr/uac
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
Metrics details
| Stars | 1,407 |
cecio/USBvalve
Expose USB activity on the fly
Metrics details
| Stars | 1,342 |
ForensicArtifacts/artifacts
Digital Forensics artifact repository
Metrics details
| Stars | 1,249 |
rng70/TryHackMe-Roadmap
a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM
Metrics details
| Stars | 1,221 |
snovvcrash/usbrip
Tracking history of USB events on GNU/Linux
Metrics details
| Stars | 1,183 |
AvillaDaniel/AvillaForensics
Avilla Forensics FREE
Metrics details
| Stars | 1,098 |
ydkhatri/mac_apt
macOS (& ios) Artifact Parsing Tool
Metrics details
| Stars | 1,065 |
thehackingsage/hackdroid
Security Apps for Android
Metrics details
| Stars | 1,063 |
google/turbinia
Automation and Scaling of Digital Forensics Tools
Metrics details
| Stars | 791 |
PaulNorman01/Forensia
Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.
Metrics details
| Stars | 788 |
kai5263499/osx-security-awesome
A collection of OSX and iOS security resources
Metrics details
| Stars | 786 |
z0m31en7/Uscrapper
Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface and deep web sources. Empower your data mining and analysis with Vanta's advanced capabilities. Fast, reliable, and user-friendly, Uscrapper Vanta is the ultimate choice for researchers and analysts.
Metrics details
| Stars | 784 |
bluecapesecurity/PWF
Practical Windows Forensics Training
Metrics details
| Stars | 777 |
williballenthin/python-evtx
Pure Python parser for Windows Event Log files (.evtx)
Metrics details
| Stars | 773 |
gaulliath/operative-framework
operative framework is a rust investigation OSINT framework, you can interact with multiple targets, execute multiple modules, create links with target, export rapport to PDF file, add note to target or results, interact with RESTFul API, write your own modules.
Metrics details
| Stars | 746 |
ashemery/LinuxForensics
Everything related to Linux Forensics
Metrics details
| Stars | 725 |
TonyPhipps/SIEM
SIEM Tactics, Techiques, and Procedures
Metrics details
| Stars | 722 |
Yamato-Security/EnableWindowsLogSettings
Documentation and scripts to properly enable Windows event logs.
Metrics details
| Stars | 709 |
cristianzsh/forensictools
Collection of forensic tools
Metrics details
| Stars | 702 |
CScorza/OSINT-FORENSICS-MOBILE
Tools OSINT MOBILE
Metrics details
| Stars | 689 |
Nhoya/gOSINT
OSINT Swiss Army Knife
Metrics details
| Stars | 672 |
alphaSeclab/awesome-forensics
Awesome Forensics Resources. Almost 300 open source forensics tools, and 600 blog posts about forensics.
Metrics details
| Stars | 668 |
stuhli/awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
Metrics details
| Stars | 661 |
awslabs/aws-security-automation
Collection of scripts and resources for DevSecOps and Automated Incident Response Security
Metrics details
| Stars | 633 |
Netflix-Skunkworks/diffy
:no_entry: (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
Metrics details
| Stars | 629 |
