
Digital Forensics Intelligence Framework
███████╗ ██████╗ ██████╗ ███████╗███╗ ██╗███████╗██╗██╗ ██╗
██╔════╝██╔═══██╗██╔══██╗██╔════╝████╗ ██║██╔════╝██║╚██╗██╔╝
█████╗ ██║ ██║██████╔╝█████╗ ██╔██╗ ██║███████╗██║ ╚███╔╝
██╔══╝ ██║ ██║██╔══██╗██╔══╝ ██║╚██╗██║╚════██║██║ ██╔██╗
██║ ╚██████╔╝██║ ██║███████╗██║ ╚████║███████║██║██╔╝ ██╗
╚═╝ ╚═════╝ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═══╝╚══════╝╚═╝╚═╝ ╚═╝
The problem ForensiX solves: No existing open-source CLI tool unifies multi-hash computation, MACB timestamp forensics, deep string classification, YARA-style pattern scanning, steganography detection, live system acquisition, disk image parsing, and court-ready report generation — all in a single portable Python script with zero external dependencies.
| Feature | Description |
|---|---|
hash | Multi-algorithm hashing (MD5/SHA1/SHA256/SHA512/SHA3/BLAKE2) + tamper verification |
meta | MACB timestamps, entropy analysis, permissions, inode, extension mismatch detection |
strings | Auto-classified string extraction: URLs, IPs, emails, credentials, JWT, AWS keys, onion addresses, CVEs |
scan | YARA-style pattern matching: ransomware, shellcode, C2 frameworks, webshells, crypto miners, credential dumpers |
hex | Forensic hex viewer with offset/length control and ASCII sidebar |
steg | Steganography detection via entropy analysis, EOF marker checks, polyglot detection |
timeline | MACB timeline reconstruction from files/directories with time filtering |
live | Live system acquisition: processes, network connections, environment |
disk | Raw disk image analysis: MBR, partition table, filesystem detection |
report | Full forensic report in TXT / JSON / HTML / CSV (chain-of-custody format) |
# No installation needed — pure Python stdlib
python3 forensix.py --help
# Or make it executable
chmod +x forensix.py
./forensix.py --help
python3 forensix.py hash malware.exe
python3 forensix.py hash malware.exe --verify d41d8cd98f00b204e9800998ecf8427e
python3 forensix.py meta evidence.jpg
python3 forensix.py meta suspicious.dll --output meta_report.html --format html
python3 forensix.py strings payload.bin --limit 100
python3 forensix.py strings memory_dump.raw --all --output strings.json --format json
python3 forensix.py scan dropper.exe
python3 forensix.py scan webshell.php --output threat_report.html --format html
python3 forensix.py hex file.bin --offset 0x100 --length 1024
python3 forensix.py steg image.jpg logo.png photo.bmp
python3 forensix.py timeline /var/log /home/user
python3 forensix.py timeline /incident --start 2024-06-01 --end 2024-06-15 --limit 200
python3 forensix.py live
python3 forensix.py live --output live_snapshot.json --format json
python3 forensix.py disk drive.dd
python3 forensix.py disk evidence.img --output disk_analysis.html --format html
python3 forensix.py report suspect.exe --format html --output case_001_report.html
python3 forensix.py report evidence.zip --format json --output case_001.json
Pure Python 3.8+ standard library only. No pip installs. No compilation. Drop it on any system and run.
Other tools (strings, binwalk) dump raw strings. ForensiX automatically classifies them into 15+ forensic categories with false-positive filtering.
Generates legally-formatted chain-of-custody reports in TXT, JSON, HTML, and CSV. No other open-source CLI tool does this out of the box.
Detects hidden data through statistical entropy analysis and file structure validation — no external libraries required.
Every file scan includes byte-level entropy calculation classified into forensically meaningful levels.
| Rule | Severity | What It Detects |
|---|---|---|
| RANSOMWARE_STRINGS | CRITICAL | Ransom notes, encryption strings, payment demands |
| SHELLCODE_INDICATORS | HIGH | NOP sleds, INT3 breakpoints, memory injection APIs |
| CREDENTIAL_DUMP | CRITICAL | Mimikatz, LSASS access, NTLM/SAM references |
| PERSISTENCE_MECHANISMS | HIGH | Registry run keys, cron jobs, scheduled tasks |
| NETWORK_TOOLS | CRITICAL | Cobalt Strike, Metasploit, Sliver, Havoc C2 |
| ANTI_FORENSICS | HIGH | Log clearing, timestomping, secure deletion |
| CRYPTO_MINERS | MEDIUM | XMRig, stratum protocol, mining pool strings |
| WEBSHELL_INDICATORS | CRITICAL | PHP eval/exec, command injection patterns |
| Format | Best For |
|---|---|
txt | Human reading, court documentation |
json | SIEM integration, further processing |
html | Reports to share with stakeholders |
csv | Spreadsheet import, data analysis |
live command on some systemsAmeer Rasim
Digital Forensics & Cybersecurity
License: MIT
ForensiX is designed for authorized forensic investigations only. Use only on systems and files you own or have explicit written permission to analyze. The author assumes no responsibility for misuse.