
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Regipy is an os independent python library for parsing offline registry hives

Hunt down social media accounts by username across social networks

Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Automate the creation of a lab environment complete with security tooling and logging best practices

OS X Auditor is a free Mac OS X computer forensics tool

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Distributed & real time digital forensics at the speed of the cloud

E-Mail Header Analyzer

Incident Response Forensic Framework

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

System-based incident response tracking application for managing large-scale DFIR cases, with import/export, task workflows, and artifact tracking…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Automated, Collection, and Enrichment Platform

Labtainers: A Docker-based cyber lab framework

PowerShell module for Office 365 and Azure log collection