#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.
Program for determining types of files for Windows, Linux and MacOS.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Free hands-on digital forensics labs for students and faculty

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…


A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Main repo for hosting release binaries

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

iOS/macOS Research Swiss Army Knife

Remove visible and invisible AI watermarks and provenance metadata from images and video. Python library and CLI for SynthID, C2PA, EXIF, IPTC, XMP,…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Hunt down social media accounts by username across social networks

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…