Authorized use only

Forensics & pentesting code library.

A curated NanoDeck resource pack for digital forensics, ethical penetration testing, blockchain forensics, AI-assisted security triage, and professional reporting. Every offensive-security-adjacent item is framed for explicit authorization, written scope, and non-destructive validation.

30
resources
5
categories
30
manifest entries
100%
authorized-use framed

Ethical use requirement

These resources are for authorized defensive security, digital forensics, compliance, education, CTF labs, and professional assessments only. Users must follow written scope, legal authority, rate limits, data handling requirements, and responsible reporting expectations.

8 assets

Digital Forensics

Pythonbeginner

File Metadata Extractor

Python script that walks evidence files and exports filesystem metadata, hashes, MIME guesses, and optional EXIF summaries.

Open resource →
Markdownintermediate

Disk Image Analysis Template

Markdown worksheet for acquisition notes, integrity verification, partition triage, timelines, and findings logs.

Open resource →
Pythonbeginner

Log Timeline Reconstructor

Python parser that normalizes ISO-8601, syslog, and web access-log timestamps into a sorted timeline CSV.

Open resource →
Markdownintermediate

Memory Forensics Starter Kit

Volatility 3 command patterns and evidence table for Windows and Linux memory-image triage.

Open resource →
Pythonintermediate

Packet Analysis Script

Scapy-based PCAP summarizer that extracts conversations, ports, lengths, and DNS queries for authorized captures.

Open resource →
Markdownbeginner

Wireshark Display Filter Starter Set

Practical display filters for DNS, HTTP, TLS, TCP resets, SMB, Kerberos, DHCP, and cleartext indicator triage.

Open resource →
Pythonintermediate

File Carving Template

Bounded carving starter for PNG, JPG, PDF, ZIP, and PE signatures from authorized binary images.

Open resource →
Pythonbeginner

Hash Verification Tool

SHA-256 manifest creator and verifier for evidence integrity workflows.

Open resource →

10 assets

Penetration Testing

Pythonintermediate

Authorized Nmap Wrapper

Conservative Nmap service-discovery wrapper that requires an explicit JSON scope file before scanning.

Open resource →
JSONbeginner

Recon Scope Example

JSON template for authorized targets, exclusions, contacts, and approved testing windows.

Open resource →
Markdownbeginner

OWASP Top 10 Web Testing Checklist

Authorized web app testing checklist covering OWASP Top 10 categories with evidence capture guidance.

Open resource →
Pythonbeginner

Web Security Header Check

Python script that reviews common browser security headers for authorized applications.

Open resource →
Pythonbeginner

Password Policy Audit Script

Consent-based password quality checker that avoids cracking, login attempts, and credential harvesting.

Open resource →
Pythonintermediate

SSL/TLS Configuration Audit

Python TLS snapshot tool for certificate issuer, expiry, SANs, negotiated protocol, and cipher review.

Open resource →
Pythonintermediate

API Security Test Template

JSON-driven requests-based smoke test runner for auth, method handling, and schema validation expectations.

Open resource →
JSONbeginner

API Test Plan Example

Example JSON plan for unauthenticated access, invalid payload, and unsupported method checks.

Open resource →
Pythonintermediate

Passive Subdomain Enumerator

DNS-resolution based subdomain discovery script for domains explicitly authorized in scope.

Open resource →
Markdownbeginner

Vulnerability Report Template

Professional finding template with ethical notice, severity, evidence, impact, remediation, and references.

Open resource →

5 assets

Crypto / Blockchain Forensics

Pythonadvanced

Blockchain Address Tracing Script

Web3.py reference script for tracing recent Ethereum transactions tied to a known address.

Open resource →
Pythonintermediate

Transaction Graph Analysis Template

CSV-to-Graphviz script that summarizes address-to-address transaction relationships.

Open resource →
Markdownadvanced

Solidity Smart Contract Audit Checklist

Checklist for access control, asset handling, reentrancy, accounting, oracle risk, upgrades, and testing evidence.

Open resource →
Markdownintermediate

Wallet Forensics Reference Guide

Guide for lawful wallet incident intake, evidence sources, triage workflow, and reporting fields.

Open resource →
Pythonadvanced

On-Chain Data Extraction Script

Web3.py exporter for block transaction metadata from an authorized RPC endpoint.

Open resource →

3 assets

AI-Assisted Security Tools

Pythonintermediate

AI Log Anomaly Detection

Scikit-learn IsolationForest pipeline that flags unusual defensive log messages for analyst review.

Open resource →
Pythonintermediate

Automated CVE Lookup Report

NVD API client that produces a defensive markdown CVE report for product or package keywords.

Open resource →
Markdownbeginner

LLM Vulnerability Description Generator Template

Prompt template and review checklist for human-reviewed vulnerability report drafting with redacted evidence.

Open resource →

4 assets

Documentation & Guides

Markdownbeginner

Legal and Ethical Use Disclaimer

Reusable disclaimer defining authorized use, user commitments, prohibited behavior, and evidence handling.

Open resource →
Markdownbeginner

Penetration Testing Rules of Engagement

Scope and rules-of-engagement template covering authorization, assets, rate limits, data handling, and sign-off.

Open resource →
Markdownbeginner

Professional Pentest Report Template

Markdown report template suitable for Word conversion with executive summary, methodology, findings, and appendices.

Open resource →
Markdownbeginner

CTF Starter Guide

Beginner-friendly guide to legal CTF practice, lab setup, categories, workflow, and safe rules.

Open resource →