
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Dshell is a network forensic analysis framework.


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Labtainers: A Docker-based cyber lab framework

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.


This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Volatility 3 ported to Rust. Same output, much faster.

An advanced memory forensics framework

UNIX-like reverse engineering framework and command-line toolset.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Open source Android Forensics app and framework