File Metadata Extractor
Python script that walks evidence files and exports filesystem metadata, hashes, MIME guesses, and optional EXIF summaries.
Open resource →A curated NanoDeck resource pack for digital forensics, ethical penetration testing, blockchain forensics, AI-assisted security triage, and professional reporting. Every offensive-security-adjacent item is framed for explicit authorization, written scope, and non-destructive validation.
These resources are for authorized defensive security, digital forensics, compliance, education, CTF labs, and professional assessments only. Users must follow written scope, legal authority, rate limits, data handling requirements, and responsible reporting expectations.
8 assets
Python script that walks evidence files and exports filesystem metadata, hashes, MIME guesses, and optional EXIF summaries.
Open resource →Markdown worksheet for acquisition notes, integrity verification, partition triage, timelines, and findings logs.
Open resource →Python parser that normalizes ISO-8601, syslog, and web access-log timestamps into a sorted timeline CSV.
Open resource →Volatility 3 command patterns and evidence table for Windows and Linux memory-image triage.
Open resource →Scapy-based PCAP summarizer that extracts conversations, ports, lengths, and DNS queries for authorized captures.
Open resource →Practical display filters for DNS, HTTP, TLS, TCP resets, SMB, Kerberos, DHCP, and cleartext indicator triage.
Open resource →Bounded carving starter for PNG, JPG, PDF, ZIP, and PE signatures from authorized binary images.
Open resource →SHA-256 manifest creator and verifier for evidence integrity workflows.
Open resource →10 assets
Conservative Nmap service-discovery wrapper that requires an explicit JSON scope file before scanning.
Open resource →JSON template for authorized targets, exclusions, contacts, and approved testing windows.
Open resource →Authorized web app testing checklist covering OWASP Top 10 categories with evidence capture guidance.
Open resource →Python script that reviews common browser security headers for authorized applications.
Open resource →Consent-based password quality checker that avoids cracking, login attempts, and credential harvesting.
Open resource →Python TLS snapshot tool for certificate issuer, expiry, SANs, negotiated protocol, and cipher review.
Open resource →JSON-driven requests-based smoke test runner for auth, method handling, and schema validation expectations.
Open resource →Example JSON plan for unauthenticated access, invalid payload, and unsupported method checks.
Open resource →DNS-resolution based subdomain discovery script for domains explicitly authorized in scope.
Open resource →Professional finding template with ethical notice, severity, evidence, impact, remediation, and references.
Open resource →5 assets
Web3.py reference script for tracing recent Ethereum transactions tied to a known address.
Open resource →CSV-to-Graphviz script that summarizes address-to-address transaction relationships.
Open resource →Checklist for access control, asset handling, reentrancy, accounting, oracle risk, upgrades, and testing evidence.
Open resource →Guide for lawful wallet incident intake, evidence sources, triage workflow, and reporting fields.
Open resource →Web3.py exporter for block transaction metadata from an authorized RPC endpoint.
Open resource →3 assets
Scikit-learn IsolationForest pipeline that flags unusual defensive log messages for analyst review.
Open resource →NVD API client that produces a defensive markdown CVE report for product or package keywords.
Open resource →Prompt template and review checklist for human-reviewed vulnerability report drafting with redacted evidence.
Open resource →4 assets
Reusable disclaimer defining authorized use, user commitments, prohibited behavior, and evidence handling.
Open resource →Scope and rules-of-engagement template covering authorization, assets, rate limits, data handling, and sign-off.
Open resource →Markdown report template suitable for Word conversion with executive summary, methodology, findings, and appendices.
Open resource →Beginner-friendly guide to legal CTF practice, lab setup, categories, workflow, and safe rules.
Open resource →