Skip to content
@fox-it

Fox-IT

Part of NCC Group

Popular repositories Loading

  1. dissect dissect Public

    Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (pa…

    1k 72

  2. aclpwn.py aclpwn.py Public

    Active Directory ACL exploitation with BloodHound

    Python 730 106

  3. Invoke-ACLPwn Invoke-ACLPwn Public

    PowerShell 523 88

  4. log4j-finder log4j-finder Public

    Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

    Python 436 95

  5. cve-2019-1040-scanner cve-2019-1040-scanner Public

    Python 296 56

  6. dissect.cstruct_legacy dissect.cstruct_legacy Public

    A no-nonsense c-like structure parsing library for Python

    Python 240 24

Repositories

Showing 10 of 87 repositories
  • dissect.target Public

    The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collections (a.k.a. targets).

    Python 68 AGPL-3.0 63 146 (1 issue needs help) 33 Updated Jul 9, 2025
  • dissect.cstruct Public

    A Dissect module implementing a parser for C-like structures.

    Python 50 Apache-2.0 20 13 (1 issue needs help) 3 Updated Jul 9, 2025
  • dissect-docs Public

    Dissect documentation project

    8 AGPL-3.0 7 4 1 Updated Jul 4, 2025
  • dissect.util Public

    A Dissect module implementing various utility functions for the other Dissect modules.

    Python 3 Apache-2.0 7 12 7 Updated Jul 4, 2025
  • dissect.fve Public

    A Dissect module implementing a parsers for full volume encryption implementations, currently Microsoft's Bitlocker Disk Encryption (BDE) and Linux Unified Key Setup (LUKS1 and LUKS2).

    Python 4 AGPL-3.0 2 3 3 Updated Jul 3, 2025
  • dissect.etl Public

    A Dissect module implementing a parser for Event Trace Log (ETL) files, used by the Windows operating system to log kernel events.

    Python 4 AGPL-3.0 3 3 1 Updated Jun 30, 2025
  • flow.record Public

    Recordization library

    Python 9 AGPL-3.0 13 5 2 Updated Jun 30, 2025
  • dissect.vmfs Public

    Dissect module implementing a parser for the VMFS file system, used by VMware virtualization software.

    Python 4 AGPL-3.0 2 3 1 Updated Jun 30, 2025
  • citrix-netscaler-triage Public

    Dissect triage script for Citrix NetScaler devices

    Python 32 Apache-2.0 11 0 0 Updated Jun 30, 2025
  • acquire Public

    acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.

    Python 104 AGPL-3.0 33 34 (5 issues need help) 7 Updated Jun 26, 2025

Most used topics

Loading…