#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…
Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Dshell is a network forensic analysis framework.

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

iOS/macOS Research Swiss Army Knife

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…