
FACT
Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

An advanced memory forensics framework

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Volatility 3 ported to Rust. Same output, much faster.

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Dshell is a network forensic analysis framework.

A free, open-source, and cross-platform iDevice management tool