Timestomping malware detection framework + arena with RL agent baselines, based on Doctor Who.
-
Updated
Jun 12, 2026 - Python
Timestomping malware detection framework + arena with RL agent baselines, based on Doctor Who.
From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe
🥷 PowerShell script for cleaning Windows forensic artifacts
Project for Computer Forensics and Cyber Crime Analysis Exam @ Polito - An interactive forensic serious game for identifying anti-forensic techniques across filesystem, memory, and network domains.
Add a description, image, and links to the timestomping topic page so that developers can more easily learn about it.
To associate your repository with the timestomping topic, visit your repo's landing page and select "manage topics."