#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Linux Evidence Acquisition Framework

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

Collaborative Incident Response platform

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

It was developed to speed up the processes of SOC Analysts during analysis

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

macOS forensic timeline generator using the analysis result DBs of mac_apt

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Log what files are accessed by any Linux process

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Blue Team detection lab created with Terraform and Ansible in Azure.

Artifact collection tool for *nix systems

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Script for automating Linux memory capture and analysis

Self-hosted incident response platform with ticket management, automated reaction playbooks, task tracking, and dashboards for streamlining alert…