Skip to content
View harelsegev's full-sized avatar

Block or report harelsegev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Parser for Windows PowerShell script block logs

Python 15 4 Updated Nov 4, 2025

Libewf is a library to access the Expert Witness Compression Format (EWF)

C 298 82 Updated Dec 20, 2025

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digi…

C++ 2,973 671 Updated Jan 24, 2026

This project aims to enhance the working environment on Windows

C 31,422 1,276 Updated Nov 3, 2025

Library and tools to access the Windows New Technology File System (NTFS)

C 226 57 Updated Dec 16, 2025

Extract and Visualize Data from URLs using Unfurl

Python 710 65 Updated Jan 29, 2026

Browser forensics tool for Google Chrome (and other Chromium-based browsers)

Python 1,374 175 Updated Feb 3, 2026

Volatility 3.0 development

Python 3,870 620 Updated Jan 31, 2026

Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.

C# 43 5 Updated Oct 25, 2024

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (pa…

1,067 80 Updated Nov 25, 2025

Construct: Declarative data structures for python that allow symmetric parsing and building

Python 995 165 Updated Apr 22, 2025

MemProcFS

C 3,987 504 Updated Jan 28, 2026

A fast, clean, responsive Hugo theme.

HTML 13,053 3,326 Updated Jan 25, 2026

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out ther…

Ruby 218 23 Updated Dec 30, 2025

A demo of some living-off-the-land techniques

5 Updated Aug 5, 2022

Compile type annotated Python to fast C extensions

1,914 47 Updated Apr 17, 2023

A place for all my DFIR ramblings

HTML 3 Updated Oct 29, 2022

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Python 3,861 516 Updated Feb 3, 2026

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Python 21,002 1,389 Updated Mar 5, 2025

A small util to brute-force prefetch hashes

Rust 77 12 Updated Jun 24, 2022

egui: an easy-to-use immediate mode GUI in Rust that runs on both web and native

Rust 27,968 1,945 Updated Feb 3, 2026

OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat and <UserCid>.dat.previous file.

Python 226 25 Updated Jan 6, 2026

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifa…

HTML 641 50 Updated Nov 7, 2025

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

C++ 592 112 Updated Jul 23, 2023

Library to handle the files in zff format (file format to store and handle forensic acquisitions).

Rust 21 1 Updated Jan 25, 2026

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust 3,438 298 Updated Oct 12, 2025

Super timeline all the things

Python 2,005 405 Updated Jan 24, 2026

Yet another registry parser

Python 138 15 Updated Apr 15, 2022

Carve file metadata from NTFS index ($I30) attributes

Python 71 5 Updated Feb 3, 2024

An NTFS/FAT parser for digital forensics & incident response

Python 217 33 Updated Oct 31, 2025