#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

A forensic evidence collection & analysis toolkit for OS X

VirusTotal Wanna Be - Now with 100% more Hipster

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Distributed & real time digital forensics at the speed of the cloud

Tracking history of USB events on GNU/Linux

Distributed alerting for the masses!

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…


A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Graph platform for Detection and Response

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.