#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Reproduce DeFi hacked incidents using Foundry.
Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

A powerful and user-friendly binary analysis platform!

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Program for determining types of files for Windows, Linux and MacOS.

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Cheat Engine. A development environment focused on modding

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Tools and Techniques for Blue Team / Incident Response

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Malware Configuration And Payload Extraction

A repository of sysmon configuration modules

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux