{"adoption": {"forks": 85, "observed_at": "2026-08-28T04:03:46.173703+00:00", "stars": 1148}, "canonical_url": "https://ross.abutalabs.com/products/dissect", "card": {"archived": false, "artifact_type": "framework", "description": "Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).", "domain": ["security", "developer-tools"], "enriched": true, "function": ["parser", "file-system", "cli", "security"], "health_score": 79, "homepage": "https://docs.dissect.tools/en/latest/", "language": null, "license": "AGPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["fox-it/dissect"], "name": "fox-it/dissect", "platform": ["python", "cli", "windows", "cross-platform"], "pushed_at": "2026-02-25T14:09:37+00:00", "repo": "fox-it/dissect", "stars": 1148, "tags": ["dfir", "incident-response", "digital-forensics", "disk-images", "artifact-parsing", "target-query", "target-shell", "acquire", "forensics", "command-line", "linux", "macos"], "topics": ["dfir", "dissect", "python"], "urls": [], "use_cases": ["parse Windows Event Logs from an E01 disk image", "extract MFT entries from a VMDK or QCoW without mounting", "collect forensic artefacts from endpoints with Acquire", "analyse Runkeys and Prefetch files from a Linux or Windows image", "build custom DFIR tooling from modular parser libraries", "triage running VMs on a hypervisor"], "what_it_is": "Dissect is a modular digital forensics and incident response (DFIR) framework and toolset by Fox-IT that parses forensic artefacts from many disk image, container, filesystem, and OS formats. It provides tools like target-query and target-shell for uniform access to artefacts, plus Acquire for lightweight endpoint acquisition.", "when_to_avoid": ["you need a GUI-based forensic suite with visual timeline analysis", "you require a license more permissive than AGPL-3.0 for commercial embedding", "you only need one-off parsing of a single well-supported file format with a simpler tool"], "when_to_choose": ["you need a single unified tool to parse artefacts across disk formats, filesystems, and operating systems", "you want scriptable, modular Python libraries for forensic parsing", "you need to acquire lightweight forensic images from live endpoints or hypervisors"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/dissect", "repo": "fox-it/dissect", "role": "main", "score": 72}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:46.173703+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:33:50.092521+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "04c5013f3cb9a15a3fa8ce230d1ed5a8c24e293195c631e5ab0e03d3337e3b17", "fetched_at": "2026-08-28T04:03:46.173703+00:00", "kind": "readme", "missing": false, "url": "https://github.com/fox-it/dissect"}, {"content_hash": "b30a967faacaf8d6631c840fac4afcd59cf519f7d0340c765b1ec58106a95ba7", "fetched_at": "2026-08-29T12:39:48.278190+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/dissect/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 69, "longevity": 100, "rhythm": 60}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1504, "days_push": 189, "days_rel": 188, "gap_med": 76.0, "n_releases_24m": 9}, "score": 72, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}