puffyCid / artemis
A cross platform forensic parser written in Rust!
☆80Updated last week
Alternatives and similar repositories for artemis:
Users that are interested in artemis are comparing it to the libraries listed below
- A parser for the MFT (Master File Table) format☆137Updated last year
- Rust bindings for VirusTotal/Yara☆75Updated last month
- Framework definitions that allow to build a custom SIEM.☆25Updated 6 months ago
- Safe and performant YARA rules evaluator in Rust☆46Updated last week
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆27Updated last month
- A Windows registry file parser written in Rust☆37Updated last year
- A document tagging library☆30Updated 3 weeks ago
- LOKI2 - Simple IOC and YARA Scanner☆89Updated 8 months ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆44Updated this week
- Basically a KrabsETW rip-off written in Rust☆69Updated 8 months ago
- Alternative YARA scanning engine☆70Updated 2 years ago
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access…☆57Updated this week
- lnk_parser is a full rust implementation to parse windows LNK files☆18Updated 3 months ago
- Windows Thingies... but in Rust☆23Updated 2 years ago
- Cyber threat intelligence crates for Rust☆15Updated last year
- Takajō (鷹匠) is a Hayabusa results analyzer.☆114Updated last week
- A crate to query windows WMI in Rust☆12Updated 2 years ago
- Wrapper for TSK (Sleuth Kit) Bindings☆11Updated 2 years ago
- Rust crate for accessing keys, values, and data stored in Windows hive (registry) files.☆47Updated 2 months ago
- Safe Rust API to libesedb☆10Updated last year
- File Capability Extractor☆13Updated last month
- A literal string obfuscation library for rust projects☆78Updated last month
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates…☆63Updated 2 weeks ago
- Detect if code is running inside a virtual machine (x86 and x86-64 only).☆45Updated 3 years ago
- Artifact collection tool for *nix systems☆203Updated last year
- siquery, a Rust osquery implementation to query system information☆59Updated 2 years ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆93Updated this week
- Pure Rust fuzzy hash implementation☆22Updated 2 years ago
- Library and binaries for the reading, creating, and modification of SquashFS file systems☆136Updated this week
- A PoC Windows Minifilter Driver in pure Rust (Don't use it in production)☆50Updated last year