Skip to main content

PyForensicKit

PyForensicKit is a Linux-based digital forensics command-line toolkit designed to assist investigators in analyzing digital evidence while preserving forensic integrity.

Features

  • Cryptographic hashing (MD5, SHA1, SHA256)
  • File metadata extraction
  • Read-only evidence analysis
  • JSON, HTML, and PDF report generation
  • Modular and extensible architecture
  • File system timeline reconstruction
  • CSV and JSON timeline export
  • Evidence integrity verification
  • Case management support

Installation

Clone the repository and install dependencies:

git clone https://github.com/samuelselasi/pyforensickit.git
cd pyforensickit
pip install -r requirements.txt

Note: libmagic is required for full metadata extraction. On Ubuntu, install with:

sudo apt-get update
sudo apt-get install -y libmagic1

Usage

Basic JSON Report

Analyze evidence and save a JSON report:

python -m pyforensickit.cli.main /path/to/evidence --output report.json

Timeline CSV Export

Analyze and export file timeline as CSV:

python -m pyforensickit.cli.main /path/to/evidence --timeline-csv timeline.csv

Full Report with Integrity Verification

Generate JSON, HTML, and PDF reports while verifying evidence integrity:

python -m pyforensickit.cli.main /path/to/evidence \
    --output report.json \
    --report-html report.html \
    --report-pdf report.pdf \
    --verify-integrity \
    --case-id CASE-2026-01 \
    --investigator "John Doe" \
    --description "Baseline system analysis"

CLI Options

Option Description
path Path to evidence file or directory
-o, --output Save forensic report to JSON file
--timeline-csv Export timeline to CSV file
--case-id Forensic case identifier
--investigator Investigator name
--description Brief case description
--verify-integrity Verify evidence integrity before and after analysis
--report-html Generate an HTML report
--report-pdf Generate a PDF report

Example Case Workflow

  1. Create a forensic case report:
python -m pyforensickit.cli.main /var/log --output logs.json --case-id CASE-LOGS-01 --investigator "Jane Smith"
  1. Verify evidence integrity and export full reports:
python -m pyforensickit.cli.main /home/user/evidence \
    --output case.json \
    --report-html case.html \
    --report-pdf case.pdf \
    --verify-integrity \
    --case-id CASE-2026-02 \
    --investigator "John Doe" \
    --description "Home directory analysis"
  1. Export timeline for additional analysis:
python -m pyforensickit.cli.main /home/user/evidence --timeline-csv timeline.csv

Forensic Considerations

  • Read-only analysis: No evidence modification occurs.
  • Hashing: Computes MD5, SHA1, and SHA256 directly from disk.
  • Integrity verification: Evidence hashes are verified before and after analysis.
  • Offline workflow: Designed to work without network connectivity.
  • Research and education: Intended as a learning and investigative tool, not a replacement for enterprise forensic suites.

Development & Contribution

  • Modular design allows adding new forensic modules.
  • Use pytest for running tests:
pytest -v --cov=src/pyforensickit
  • Ensure all tests pass before submitting pull requests.

Roadmap

  • Timeline reconstruction improvements
  • Deleted file recovery and analysis
  • Email and browser artifact analysis
  • Web-based reporting interface
  • Integration with third-party forensic tools

License

PyForensicKit is licensed under the MIT License.

References

Metadata

Release files for pyforensickit 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyforensickit 0.1.1
File Size Uploaded
pyforensickit-0.1.1.tar.gz 10.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyforensickit 0.1.1
File Interpreter ABI Platform
pyforensickit-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 19.1 kB

Release files / pyforensickit-0.1.1.tar.gz

Download URL pyforensickit-0.1.1.tar.gz
Size 10.0 kB
Tags Source
SHA-256 checksum
How to use checksums
e33ff272a3dd2f383a1db832fe97c556a012097b9065b32d65f67139e977230c
BLAKE2b-256 checksum
How to use checksums
bce654f944247cd2e1ef169996734dda993437a1e43417c0da6eb50bd3b852d4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.12

Release files / pyforensickit-0.1.1-py3-none-any.whl

Download URL pyforensickit-0.1.1-py3-none-any.whl
Size 9.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
08001b0e3686f81770177dc7659de28caa795d8e7c5e7259380041cdfda220e4
BLAKE2b-256 checksum
How to use checksums
50b77d974e4b35f2e29d01aa9ed7df1c9ff5a7a6ba1338e34594b4a11eea549f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.12

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page