#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

EDRSandblast-GodFault

Finding secrets in kernel and user memory

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

A frida tool to dump dex in memory to support security engineers analyzing malware.

Dump the memory of a PPL with a userland exploit

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Penetration testing utility and antivirus assessment tool.

Kirjuri is a web application for managing cases and physical forensic evidence items.

Tracking history of USB events on GNU/Linux

Distributed & real time digital forensics at the speed of the cloud

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A tool for finding and analyzing private (and public) key files, including support for Android APK files.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Python program to steganography files into images using the Least Significant Bit.