# NanoDeck Security Library Manifest

All resources are for authorized defensive security, digital forensics, compliance, education, CTF labs, and professional assessments only.

## Digital Forensics

- **File Metadata Extractor** (Python, beginner): Python script that walks evidence files and exports filesystem metadata, hashes, MIME guesses, and optional EXIF summaries.  
  Path: `/security-library/digital-forensics/file_metadata_extractor.py`
- **Disk Image Analysis Template** (Markdown, intermediate): Markdown worksheet for acquisition notes, integrity verification, partition triage, timelines, and findings logs.  
  Path: `/security-library/digital-forensics/disk_image_analysis_template.md`
- **Log Timeline Reconstructor** (Python, beginner): Python parser that normalizes ISO-8601, syslog, and web access-log timestamps into a sorted timeline CSV.  
  Path: `/security-library/digital-forensics/log_timeline_reconstructor.py`
- **Memory Forensics Starter Kit** (Markdown, intermediate): Volatility 3 command patterns and evidence table for Windows and Linux memory-image triage.  
  Path: `/security-library/digital-forensics/memory_forensics_starter.md`
- **Packet Analysis Script** (Python, intermediate): Scapy-based PCAP summarizer that extracts conversations, ports, lengths, and DNS queries for authorized captures.  
  Path: `/security-library/digital-forensics/packet_analysis.py`
- **Wireshark Display Filter Starter Set** (Markdown, beginner): Practical display filters for DNS, HTTP, TLS, TCP resets, SMB, Kerberos, DHCP, and cleartext indicator triage.  
  Path: `/security-library/digital-forensics/wireshark_filters.md`
- **File Carving Template** (Python, intermediate): Bounded carving starter for PNG, JPG, PDF, ZIP, and PE signatures from authorized binary images.  
  Path: `/security-library/digital-forensics/file_carving_template.py`
- **Hash Verification Tool** (Python, beginner): SHA-256 manifest creator and verifier for evidence integrity workflows.  
  Path: `/security-library/digital-forensics/hash_verify.py`

## Penetration Testing

- **Authorized Nmap Wrapper** (Python, intermediate): Conservative Nmap service-discovery wrapper that requires an explicit JSON scope file before scanning.  
  Path: `/security-library/pentesting/nmap_authorized_wrapper.py`
- **Recon Scope Example** (JSON, beginner): JSON template for authorized targets, exclusions, contacts, and approved testing windows.  
  Path: `/security-library/pentesting/scope.example.json`
- **OWASP Top 10 Web Testing Checklist** (Markdown, beginner): Authorized web app testing checklist covering OWASP Top 10 categories with evidence capture guidance.  
  Path: `/security-library/pentesting/owasp_web_testing_checklist.md`
- **Web Security Header Check** (Python, beginner): Python script that reviews common browser security headers for authorized applications.  
  Path: `/security-library/pentesting/web_security_header_check.py`
- **Password Policy Audit Script** (Python, beginner): Consent-based password quality checker that avoids cracking, login attempts, and credential harvesting.  
  Path: `/security-library/pentesting/password_audit.py`
- **SSL/TLS Configuration Audit** (Python, intermediate): Python TLS snapshot tool for certificate issuer, expiry, SANs, negotiated protocol, and cipher review.  
  Path: `/security-library/pentesting/tls_audit.py`
- **API Security Test Template** (Python, intermediate): JSON-driven requests-based smoke test runner for auth, method handling, and schema validation expectations.  
  Path: `/security-library/pentesting/api_security_tests.py`
- **API Test Plan Example** (JSON, beginner): Example JSON plan for unauthenticated access, invalid payload, and unsupported method checks.  
  Path: `/security-library/pentesting/api_test_plan.example.json`
- **Passive Subdomain Enumerator** (Python, intermediate): DNS-resolution based subdomain discovery script for domains explicitly authorized in scope.  
  Path: `/security-library/pentesting/subdomain_enum.py`
- **Vulnerability Report Template** (Markdown, beginner): Professional finding template with ethical notice, severity, evidence, impact, remediation, and references.  
  Path: `/security-library/pentesting/vulnerability_report_template.md`

## Crypto / Blockchain Forensics

- **Blockchain Address Tracing Script** (Python, advanced): Web3.py reference script for tracing recent Ethereum transactions tied to a known address.  
  Path: `/security-library/blockchain-forensics/address_tracing.py`
- **Transaction Graph Analysis Template** (Python, intermediate): CSV-to-Graphviz script that summarizes address-to-address transaction relationships.  
  Path: `/security-library/blockchain-forensics/transaction_graph_analysis.py`
- **Solidity Smart Contract Audit Checklist** (Markdown, advanced): Checklist for access control, asset handling, reentrancy, accounting, oracle risk, upgrades, and testing evidence.  
  Path: `/security-library/blockchain-forensics/solidity_audit_checklist.md`
- **Wallet Forensics Reference Guide** (Markdown, intermediate): Guide for lawful wallet incident intake, evidence sources, triage workflow, and reporting fields.  
  Path: `/security-library/blockchain-forensics/wallet_forensics_guide.md`
- **On-Chain Data Extraction Script** (Python, advanced): Web3.py exporter for block transaction metadata from an authorized RPC endpoint.  
  Path: `/security-library/blockchain-forensics/onchain_extraction.py`

## AI-Assisted Security Tools

- **AI Log Anomaly Detection** (Python, intermediate): Scikit-learn IsolationForest pipeline that flags unusual defensive log messages for analyst review.  
  Path: `/security-library/ai-assisted/log_anomaly_detection.py`
- **Automated CVE Lookup Report** (Python, intermediate): NVD API client that produces a defensive markdown CVE report for product or package keywords.  
  Path: `/security-library/ai-assisted/cve_lookup.py`
- **LLM Vulnerability Description Generator Template** (Markdown, beginner): Prompt template and review checklist for human-reviewed vulnerability report drafting with redacted evidence.  
  Path: `/security-library/ai-assisted/llm_vulnerability_description_template.md`

## Documentation & Guides

- **Legal and Ethical Use Disclaimer** (Markdown, beginner): Reusable disclaimer defining authorized use, user commitments, prohibited behavior, and evidence handling.  
  Path: `/security-library/docs/legal_ethical_disclaimer.md`
- **Penetration Testing Rules of Engagement** (Markdown, beginner): Scope and rules-of-engagement template covering authorization, assets, rate limits, data handling, and sign-off.  
  Path: `/security-library/docs/rules_of_engagement_template.md`
- **Professional Pentest Report Template** (Markdown, beginner): Markdown report template suitable for Word conversion with executive summary, methodology, findings, and appendices.  
  Path: `/security-library/docs/professional_pentest_report_template.md`
- **CTF Starter Guide** (Markdown, beginner): Beginner-friendly guide to legal CTF practice, lab setup, categories, workflow, and safe rules.  
  Path: `/security-library/docs/ctf_starter_guide.md`
