
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Bash tool used for proactive detection of malicious activity on macOS systems.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

privacy-first, open-source and free idevice management tool written in Rust and Qt

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Imago is a python tool that extract digital evidences from images.

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

A tool for mapping cyber crime


An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

E-Mail Header Analyzer

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

A tool to use novel locations to extract metadata from Office documents.