sumeshi/mft2es
A library for fast parse & import of Windows Master File Table($MFT) into Elasticsearch.
GitHub repository with 12 stars and 4 forks.
Language: Python
Topics: dfir, elasticsearch, forensics, mft, parser, python, windows
A library for fast parse & import of Windows Master File Table($MFT) into Elasticsearch.
GitHub repository with 12 stars and 4 forks.
Language: Python
Topics: dfir, elasticsearch, forensics, mft, parser, python, windows
2026-06-05: 12 stars and 4 forks.
Browser forensics tool for Google Chrome (and other Chromium-based browsers)
GitHub repository with 1,438 stars and 180 forks.
Trending score: 0.49; stars gained: +1; forks gained: +0.
Language: Python
Topics: google-chrome, hindsight, chrome, forensics, dfir, browser-forensics
🪽Docker Compose–based AWS CloudTrail threat hunting tool. Ingests logs into DuckDB with Rust, and lets you query them in natural language via an AI-powered Streamlit UI — no SIEM, no cloud dependency.🪽
GitHub repository with 6 stars and 0 forks.
Trending score: 0.05; stars gained: +0; forks gained: +0.
Language: Python
Topics: aws, cloud, cloudtrail, siem, threathunting, dfir
🔍 Transform source code into actionable security insights with the Code-First Automated Threat Modeling Toolkit for deep risk analysis.
GitHub repository with 6 stars and 1 forks.
Trending score: 0.05; stars gained: +0; forks gained: +0.
Language: Python
Topics: dfir, german, hacktoberfest2020, hacktoberfest2021, hacktoberfest2024, hunter
The agent that grows with you
GitHub repository with 181,588 stars and 31,155 forks.
Trending score: 5.95; stars gained: +1,867; forks gained: +361.
Language: Python
Topics: ai, ai-agent, ai-agents, anthropic, chatgpt, claude
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answers. Library, proxy, MCP server.
GitHub repository with 13,361 stars and 853 forks.
Trending score: 5.69; stars gained: +2,829; forks gained: +175.
Language: Python
Topics: agent, ai, anthropic, compression, context-engineering, context-window
Academic Research Skills for Claude Code: research → write → review → revise → finalize
GitHub repository with 27,422 stars and 2,253 forks.
Trending score: 5.52; stars gained: +1,079; forks gained: +89.
Language: Python
Topics: academic-pipeline, academic-writing, ai-research, claude, claude-code, literature-review
GitHub repository with 30,002 stars and 4,224 forks.
Trending score: 4.88; stars gained: +688; forks gained: +114.
Language: Python
Turn any technical book PDF into a Claude Code skill — ready to study, reference, and use while you work.
GitHub repository with 4,250 stars and 534 forks.
Trending score: 4.88; stars gained: +476; forks gained: +68.
Language: Python
An opinionated list of Python frameworks, libraries, tools, and resources
GitHub repository with 301,371 stars and 28,044 forks.
Trending score: 4.60; stars gained: +518; forks gained: +24.
Language: Python
Topics: awesome, python, collections, python-frameworks, python-libraries, python-tools
Awesome Security lists for SOC/CERT/CTI
GitHub repository with 1,496 stars and 178 forks.
Trending score: 1.58; stars gained: +7; forks gained: +1.
Language: YARA
Topics: awesome-list, blueteam, blueteam-tools, cti, detection, detection-engineering
MESH enables internet-routable wireless ADB debugging for Android through an end-to-end encrypted, censorship-resistant mesh network, supporting mobile forensics and network monitoring beyond the limits of local Wi-Fi or LAN access.
GitHub repository with 101 stars and 12 forks.
Trending score: 1.06; stars gained: +1; forks gained: +1.
Language: Kotlin
Topics: blue-team, dfir, forensics, forensics-tools, mobile, spyware-detection
Browser forensics tool for Google Chrome (and other Chromium-based browsers)
GitHub repository with 1,438 stars and 180 forks.
Trending score: 0.49; stars gained: +1; forks gained: +0.
Language: Python
Topics: google-chrome, hindsight, chrome, forensics, dfir, browser-forensics
A cross platform forensic parser written in Rust!
GitHub repository with 112 stars and 13 forks.
Trending score: 0.14; stars gained: +0; forks gained: +0.
Language: Rust
Topics: digital-forensics, incident-response, rust, dfir
🪽Docker Compose–based AWS CloudTrail threat hunting tool. Ingests logs into DuckDB with Rust, and lets you query them in natural language via an AI-powered Streamlit UI — no SIEM, no cloud dependency.🪽
GitHub repository with 6 stars and 0 forks.
Trending score: 0.05; stars gained: +0; forks gained: +0.
Language: Python
Topics: aws, cloud, cloudtrail, siem, threathunting, dfir
Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" macOS binaries and how they can be used by threat actors for malicious purposes.
GitHub repository with 540 stars and 68 forks.
Trending score: 0.05; stars gained: +0; forks gained: +0.
Language: Astro
Topics: blueteam, cybersecurity, detection, dfir, redteam, living-off-the-land