Crush — Digital Forensic Analysis Workbench
Open and navigate ZIP, TAR, 7z, Android adb backup (.ab), and iTunes/Finder iOS backup archives, folders, and individual files without extracting anything to disk first. Mobile backups are reconstructed as the original device filesystem — iOS backups rebuild the domain/relativePath tree from Manifest.db instead of the flat, hash-named layout on disk; Android backups unpack as a regular filesystem tree.
Password-protected archives — ZIP (both legacy ZipCrypto and WinZip AES), 7z, encrypted Android backups, and password-protected iTunes backups all prompt for a password when opened, with a retry on a wrong one.
Built-in file format database — Crush identifies forensically relevant formats by magic bytes and extension, and shows format name, platform, forensic relevance, and a link to the specification for every selected file, including formats without a dedicated viewer.
Integrity mode — optional hashing for auditability: file/ZIP/TAR sources are hashed on open and exports generate a hash manifest (crush-export-hashes.txt). Toggle via the bottom-right status badge.
Send to Peach — hand a log source (Apple Unified Log, or any other file — same "no pre-filtering, confirm in the tool itself" approach as Multi-Log Studio) off to the bundled sibling log viewer peach-forensics for tagging and Splunk-style search, via right-click.
Supported viewers (more planned):
- SQLite / Database Viewer
- Hex Viewer
- Text Viewer (with syntax highlighting and encoding detection)
- JSON Viewer (collapsible tree)
- XML Viewer (collapsible tree)
- Plist / BPlist Viewer
- SEGB v1/v2 Viewer
- ABX (Android Binary XML) Viewer
- LevelDB Viewer (Chrome LevelDB / Android app databases)
- Image Viewer
- Media Viewer (audio/video)
- Multi-Log Studio (multi-source log analysis, format auto-detection)
- Protobuf Viewer (schema-less; optional schema decoding)
- PDF Viewer (page rendering, text extraction, revision history)
- Realm Database Viewer (schema and table decoding)
→ User Handbook → Format Support & Parser Limitations
Technical write-ups on the crush viewers — forensic background, workflow, and what to look for:
| Viewer | Post |
|---|---|
| SQLite | What Hides in the WAL — SQLite Forensics with crush |
| RealmDB | Object by Object — RealmDB Forensics with crush |
| LevelDB | Reading the CURRENT — LevelDB Forensics with crush |
| SEGB / Biome | Beyond the C — SEGB and Biome Forensics with crush |
| Protobuf | Reading Protobuf Wire Format Without a Map |
Loading Speed - How fast we can load from zips

macOS (Homebrew)
brew tap kalink0/forensics
brew install --cask crush-forensicsWindows (winget)
winget install kalink0.CrushWindows (Scoop)
scoop bucket add forensics https://github.com/kalink0/scoop-forensics
scoop install forensics/crush-forensicsNo native package for Linux yet — grab the AppImage from Releases.
- Create a virtual environment
python -m venv .venv
source .venv/bin/activate- Install dependencies
python -m pip install --upgrade pip
python -m pip install -e .- Download the Unified Log parser binaries (required for Apple
.tracev3/.logarchivesupport)
python scripts/download_unifiedlog_binaries.py- Download the peach-forensics binaries (required for the "Send to Peach" log-viewer handoff)
python scripts/download_peach_binaries.py- Run Crush
crushpython -m crushIf you see missing Qt or media errors, install the system dependencies below.
crush /path/to/evidence.zip /path/to/case_folder
crush --open /path/to/evidence.zip --open /path/to/case_folderPositional paths and --open PATH (repeatable) are equivalent — each opens
that file or folder on startup, added to the same window's tree. Every
invocation opens a new window.
Some Python packages require OS-level libraries on fresh machines.
These are required for the Qt GUI to run correctly on Linux.
- Debian/Ubuntu:
sudo apt-get install libgl1 libegl1 libxcb-xinerama0 libxkbcommon-x11-0 - Fedora:
sudo dnf install mesa-libGL mesa-libEGL libxcb libxkbcommon-x11 - Arch:
sudo pacman -S mesa libglvnd libxcb libxkbcommon-x11 - Windows: no additional packages required; if the app fails to start, install the Microsoft Visual C++ Redistributable 2015-2022 (x64)
- macOS: no additional packages required (bundled with the OS)
python-magic depends on libmagic being present on the system.
- Debian/Ubuntu:
sudo apt-get install libmagic1 - Fedora:
sudo dnf install file-libs - Arch:
sudo pacman -S file - macOS (Homebrew):
brew install libmagic - Windows: no additional packages required
PySide6 uses system multimedia backends.
- Debian/Ubuntu:
sudo apt-get install gstreamer1.0-plugins-base gstreamer1.0-plugins-good - Fedora:
sudo dnf install gstreamer1-plugins-base gstreamer1-plugins-good - Arch:
sudo pacman -S gstreamer gst-plugins-base gst-plugins-good - macOS: typically bundled with Qt; if media playback fails, install
gstreamer - Windows: typically bundled with Qt; no additional packages required
For Linux audio playback, libpulse is commonly required by Qt Multimedia.
- Debian/Ubuntu:
sudo apt-get install libpulse0 - Fedora:
sudo dnf install pulseaudio-libs - Arch:
sudo pacman -S libpulse
This project builds on the great work of the DFIR community. The following third-party modules by CCL Solutions Group are bundled:
- ccl_bplist — Binary plist module (BSD 3-Clause)
- ccl_segb — SEGB (Significant Energy Bearer) module (MIT)
- ccl_leveldb — LevelDB / Chrome LevelDB module (MIT)
Apple Unified Log (.tracev3 / .logarchive) parsing uses the macos-UnifiedLogs unifiedlog_iterator binary by Mandiant (Apache License 2.0). The binary is bundled automatically in portable builds. When running from source, run scripts/download_unifiedlog_binaries.py to download the platform binaries into crush/bin/unifiedlog_iterator/ (they are git-ignored and never committed).
Send to Peach hands log sources off to peach-forensics, a sibling forensic log viewer (Apache License 2.0) — tagging, Splunk-style search, no IPC after launch. Sessions aren't persisted for sources Crush had to extract or decrypt first (--ephemeral-session), so a handoff never leaves a durable, unencrypted copy of evidence behind. The binary is bundled the same way as unifiedlog_iterator; run scripts/download_peach_binaries.py when running from source to populate crush/bin/peach/.
Special thanks to @dugeonlady for suggesting the Rainbow theme — because digital forensics tools don't have to be grey. Or dark. Someone has to bring colour to the hex dump. Evidence: View → Theme → Rainbow. She was right.
Parts of this software were developed with assistance from Claude AI / Claude Code by Anthropic.
Use GitHub Issues. Please include the Crush version (shown in Help → About), your OS, and steps to reproduce.





