Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ForensiX — Digital Forensics Intelligence Framework | Kitploit
Tools/GitHubGitHub/theevidencehunter/forensix
Disk ForensicsHash AnalysisForensicsSteganographyMalware AnalysisDigital ForensicsIncident Response
GitHubtheevidencehunter/forensix

ForensiX

Digital Forensics Intelligence Framework

View Repository
245 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

⬡ ForensiX — Digital Forensics Intelligence Framework

Created by Ameer Rasim | Version 2.0.0

███████╗ ██████╗ ██████╗ ███████╗███╗   ██╗███████╗██╗██╗  ██╗
██╔════╝██╔═══██╗██╔══██╗██╔════╝████╗  ██║██╔════╝██║╚██╗██╔╝
█████╗  ██║   ██║██████╔╝█████╗  ██╔██╗ ██║███████╗██║ ╚███╔╝ 
██╔══╝  ██║   ██║██╔══██╗██╔══╝  ██║╚██╗██║╚════██║██║ ██╔██╗ 
██║     ╚██████╔╝██║  ██║███████╗██║ ╚████║███████║██║██╔╝ ██╗
╚═╝      ╚═════╝ ╚═╝  ╚═╝╚══════╝╚═╝  ╚═══╝╚══════╝╚═╝╚═╝  ╚═╝

The problem ForensiX solves: No existing open-source CLI tool unifies multi-hash computation, MACB timestamp forensics, deep string classification, YARA-style pattern scanning, steganography detection, live system acquisition, disk image parsing, and court-ready report generation — all in a single portable Python script with zero external dependencies.


🔬 Features

FeatureDescription
hashMulti-algorithm hashing (MD5/SHA1/SHA256/SHA512/SHA3/BLAKE2) + tamper verification
metaMACB timestamps, entropy analysis, permissions, inode, extension mismatch detection
stringsAuto-classified string extraction: URLs, IPs, emails, credentials, JWT, AWS keys, onion addresses, CVEs
scanYARA-style pattern matching: ransomware, shellcode, C2 frameworks, webshells, crypto miners, credential dumpers
hexForensic hex viewer with offset/length control and ASCII sidebar
stegSteganography detection via entropy analysis, EOF marker checks, polyglot detection
timelineMACB timeline reconstruction from files/directories with time filtering
liveLive system acquisition: processes, network connections, environment
diskRaw disk image analysis: MBR, partition table, filesystem detection
reportFull forensic report in TXT / JSON / HTML / CSV (chain-of-custody format)

⚡ Quick Start

# No installation needed — pure Python stdlib
python3 forensix.py --help

# Or make it executable
chmod +x forensix.py
./forensix.py --help

📖 Usage Examples

1. Hash a suspicious file and verify integrity

python3 forensix.py hash malware.exe
python3 forensix.py hash malware.exe --verify d41d8cd98f00b204e9800998ecf8427e

2. Extract all forensic metadata

python3 forensix.py meta evidence.jpg
python3 forensix.py meta suspicious.dll --output meta_report.html --format html

3. Deep string extraction with auto-classification

python3 forensix.py strings payload.bin --limit 100
python3 forensix.py strings memory_dump.raw --all --output strings.json --format json

4. Scan for malware patterns

python3 forensix.py scan dropper.exe
python3 forensix.py scan webshell.php --output threat_report.html --format html

5. Forensic hex viewer

python3 forensix.py hex file.bin --offset 0x100 --length 1024

6. Detect hidden data (steganography)

python3 forensix.py steg image.jpg logo.png photo.bmp

7. Reconstruct filesystem timeline

python3 forensix.py timeline /var/log /home/user
python3 forensix.py timeline /incident --start 2024-06-01 --end 2024-06-15 --limit 200

8. Live incident response

python3 forensix.py live
python3 forensix.py live --output live_snapshot.json --format json

9. Analyze disk image

python3 forensix.py disk drive.dd
python3 forensix.py disk evidence.img --output disk_analysis.html --format html

10. Full forensic report (all-in-one)

python3 forensix.py report suspect.exe --format html --output case_001_report.html
python3 forensix.py report evidence.zip --format json --output case_001.json

🎯 What Makes ForensiX Unique

Zero External Dependencies

Pure Python 3.8+ standard library only. No pip installs. No compilation. Drop it on any system and run.

Auto-Classified String Extraction

Other tools (strings, binwalk) dump raw strings. ForensiX automatically classifies them into 15+ forensic categories with false-positive filtering.

Court-Ready Reports

Generates legally-formatted chain-of-custody reports in TXT, JSON, HTML, and CSV. No other open-source CLI tool does this out of the box.

Steganography Detection Without ImageMagick/Pillow

Detects hidden data through statistical entropy analysis and file structure validation — no external libraries required.

Shannon Entropy Analysis

Every file scan includes byte-level entropy calculation classified into forensically meaningful levels.


🛡️ Threat Detection Rules

RuleSeverityWhat It Detects
RANSOMWARE_STRINGSCRITICALRansom notes, encryption strings, payment demands
SHELLCODE_INDICATORSHIGHNOP sleds, INT3 breakpoints, memory injection APIs
CREDENTIAL_DUMPCRITICALMimikatz, LSASS access, NTLM/SAM references
PERSISTENCE_MECHANISMSHIGHRegistry run keys, cron jobs, scheduled tasks
NETWORK_TOOLSCRITICALCobalt Strike, Metasploit, Sliver, Havoc C2
ANTI_FORENSICSHIGHLog clearing, timestomping, secure deletion
CRYPTO_MINERSMEDIUMXMRig, stratum protocol, mining pool strings
WEBSHELL_INDICATORSCRITICALPHP eval/exec, command injection patterns

📋 Output Formats

FormatBest For
txtHuman reading, court documentation
jsonSIEM integration, further processing
htmlReports to share with stakeholders
csvSpreadsheet import, data analysis

🔧 Requirements

  • Python: 3.8 or newer
  • Dependencies: None (100% standard library)
  • OS: Linux, macOS, Windows
  • Permissions: Root/Admin required for live command on some systems

👤 Author

Ameer Rasim
Digital Forensics & Cybersecurity
License: MIT


⚠️ Legal Notice

ForensiX is designed for authorized forensic investigations only. Use only on systems and files you own or have explicit written permission to analyze. The author assumes no responsibility for misuse.

Download Tool