Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Forewalk

A lightweight, custom Python GUI forensic utility featuring signature scanning, entropy randomness analysis, and file carving capabilities. [WIP]


Overview

Forewalk is a custom desktop forensic utility built with Python and CustomTkinter, designed to provide a simple, beginner-friendly interface for binary analysis, signature inspection, and file carving.


Key Features

  • Signature Scanning: Parses files to locate structural headers and embedded containers.
  • Shannon Entropy Analysis: Measures data randomness block-by-block with visual graphs to spot hidden, packed, or encrypted payloads.
  • File Carving Integration: Built-in support using the standard foremost.exe binary (sourced from SourceForge) to extract raw data blocks. (Note: Based on testing, Foremost tends to perform more reliably on Linux environments).
  • Smart Validation: Uses strict architectural checks (such as PE header pointer verification) to eliminate false positives on clean image files.
  • Interactive Explorer & Hexed.it Integration: Built-in drag-and-drop support with instant web-tool bridging for deep hex analysis.

Supported File & Container Formats

  • Images & Documents: JPEG, PNG, GIF, PDF
  • Archives: ZIP, 7-Zip, RAR, GZIP
  • Executables: Windows PE Executables (MZ / validated PE structures)

Known Limitations & Notes

  • Signature Sensitivity & False Positives: Because binary structures (like compressed image streams or complex container formats like .docx) can occasionally mimic magic bytes or headers by pure mathematical coincidence, the scanner can sometimes be over-sensitive. Manual verification via hex viewers is always recommended.

Installation & Usage (One-Click for Beginners)

  1. Clone or download this repository.
  2. Double-click install.bat to automatically install required dependencies (customtkinter, tkinterdnd2) and launch the app.
  3. For future use, simply double-click run.bat.

Acknowledgments

  • Developed as a learning project, built with AI assistance.

Contributions & Suggestions

Suggestions, bug reports, and feedback are always welcome! Feel free to open an issue or submit a pull request.

About

A lightweight, custom Python GUI forensic utility featuring signature scanning, entropy randomness analysis, and file carving capabilities.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages