#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.


Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

FAT filesystems explore, extract, repair, and forensic tool

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Linux Distro for Mobile Security, Malware Analysis, and Forensics

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

A Swiss army knife for your daily Linux network plumbing.

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

Visualize network topologies and collect graph statistics based on pcap files

Linux Evidence Acquisition Framework

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Incident Response & Digital Forensics Debugging Extension