A lightweight, custom Python GUI forensic utility featuring signature scanning, entropy randomness analysis, and file carving capabilities. [WIP]
Forewalk is a custom desktop forensic utility built with Python and CustomTkinter, designed to provide a simple, beginner-friendly interface for binary analysis, signature inspection, and file carving.
- Signature Scanning: Parses files to locate structural headers and embedded containers.
- Shannon Entropy Analysis: Measures data randomness block-by-block with visual graphs to spot hidden, packed, or encrypted payloads.
- File Carving Integration: Built-in support using the standard
foremost.exebinary (sourced from SourceForge) to extract raw data blocks. (Note: Based on testing, Foremost tends to perform more reliably on Linux environments). - Smart Validation: Uses strict architectural checks (such as PE header pointer verification) to eliminate false positives on clean image files.
- Interactive Explorer & Hexed.it Integration: Built-in drag-and-drop support with instant web-tool bridging for deep hex analysis.
- Images & Documents: JPEG, PNG, GIF, PDF
- Archives: ZIP, 7-Zip, RAR, GZIP
- Executables: Windows PE Executables (
MZ/ validatedPEstructures)
- Signature Sensitivity & False Positives: Because binary structures (like compressed image streams or complex container formats like
.docx) can occasionally mimic magic bytes or headers by pure mathematical coincidence, the scanner can sometimes be over-sensitive. Manual verification via hex viewers is always recommended.
- Clone or download this repository.
- Double-click
install.batto automatically install required dependencies (customtkinter,tkinterdnd2) and launch the app. - For future use, simply double-click
run.bat.
- Developed as a learning project, built with AI assistance.
Suggestions, bug reports, and feedback are always welcome! Feel free to open an issue or submit a pull request.