filegrail is an open-source command-line tool for reconstructing the origins of files in a directory after the fact. It analyzes provenance and metadata such as content credentials, EXIF data, download information, GPS, and other forensic indicators for investigations.
In the Malware analysis & digital forensics space, filegrail takes a focused approach. It focuses on determining where files came from and recovering their provenance after they have been collected. filegrail is an open-source project aimed at digital forensics investigators and OSINT researchers. The project is open source (Apache-2.0). It ships for the command line, and it can be self-hosted.
osint-shifu builds and maintains filegrail, and it first shipped in 2026. Development happens publicly on GitHub with 107 commits in the last 90 days. Key capabilities include file provenance reconstruction, content credentials, and EXIF analysis.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match