{"repo":"kalink0/crush-forensics","free":true,"listed":false,"github":"https://github.com/kalink0/crush-forensics","clone":"git clone https://github.com/kalink0/crush-forensics.git","description":"Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, SQLite, SEGB, (B)PLIST, REALM, Protobuf, Logs,hex, JSON, XML, and more — all in one GUI.","language":"Python","stars":43,"topics":["android-forensics","dfir","digital-forensics","forensics","ios-forensics","mobile-forensics","open-source","plist","segb","sqlite"],"license":"Apache-2.0","category":"databases-storage","readme_excerpt":"crush-forensics Crush — Digital Forensic Analysis Workbench Features Open and navigate ZIP, TAR, 7z, Android adb backup ( .ab ), and iTunes/Finder iOS backup archives, folders, and individual files without extracting anything to disk first. Mobile backups are reconstructed as the original device filesystem — iOS backups rebuild the domain/relativePath tree from Manifest.db instead of the flat, hash-named layout on disk; Android backups unpack as a regular filesystem tree. Password-protected archives — ZIP (both legacy ZipCrypto and WinZip AES), 7z, encrypted Android backups, and password-protected iTunes backups all prompt for a password when opened, with a retry on a wrong one. Built-in file format database — Crush identifies forensically relevant formats by magic bytes and extension, and shows format name, platform, forensic relevance, and a link to the specification for every selected file, including formats without a dedicated viewer. Integrity mode — optional hashing for auditability: file/ZIP/TAR sources are hashed on open and exports generate a hash manifest ( crush-export-hashes.txt ). Toggle via the bottom-right status badge. Send to Peach — hand a log source (Apple Unified Log, or any other file — same \"no pre-filtering, confirm in the tool itself\" approach as Multi-Log Studio) off to the bundled sibling log viewer peach-forensics for tagging and Splunk-style search, via right-click. Supported viewers (more planned): - SQLite / Database Viewer - Hex Viewer - Text Vi","default_branch":null,"files":null,"tree":[],"storefront":"/r/kalink0","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kalink0/crush-forensics/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}