
BlueTeam-Tools
Tools and Techniques for Blue Team / Incident Response

Tools and Techniques for Blue Team / Incident Response

Collection of forensic tools

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

A python tool that will extract exif data from picture with two methods

Crack ios Restriction PassCode in Python

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

A tool to recover from ESXiArgs ransomware

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

WhatsApp Forensic Tool

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Search and extract blob files on the Ethereum Blockchain network

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
