#1Digital forensics, evidence collection, timeline analysis, and incident investigation tools.
Kitploit recommended

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Easy-to-use live forensics toolbox for Linux endpoints

Open source Android Forensics app and framework

CLI tools for forensic investigation of Windows artifacts

A tool for finding and analyzing private (and public) key files, including support for Android APK files.

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Differential Analysis of Malware in Memory

Automatically create YARA rules from malicious documents.

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Finding secrets in kernel and user memory

Kirjuri is a web application for managing cases and physical forensic evidence items.

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

Indicator of Compromise Scanner for CVE-2019-19781
