
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Remove visible and invisible AI watermarks and provenance metadata from images and video. Python library and CLI for SynthID, C2PA, EXIF, IPTC, XMP,…

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Easy-to-use live forensics toolbox for Linux endpoints

Regipy is an os independent python library for parsing offline registry hives

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Hunt down social media accounts by username across social networks

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Dshell is a network forensic analysis framework.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Mimikatz implementation in pure Python

Investigate malicious Windows logon by visualizing and analyzing Windows event log

OS X Auditor is a free Mac OS X computer forensics tool