
Aurora-Incident-Response
Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Bash tool used for proactive detection of malicious activity on macOS systems.

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

privacy-first, open-source and free idevice management tool written in Rust and Qt

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

E-Mail Header Analyzer

Imago is a python tool that extract digital evidences from images.

A tool for mapping cyber crime

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A python tool that will extract exif data from picture with two methods

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox