
pftriage
Python tool and library to help analyze files during malware triage and analysis.

Python tool and library to help analyze files during malware triage and analysis.

IoT firmware identification and extraction

OpenStego is a steganography application that provides two functionalities: a) Data Hiding: It can hide any data within an image file. b)…

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Free hands-on digital forensics labs for students and faculty

Extracts and decrypts inner payloads from Donut obfuscator samples by detecting loader shellcode signatures, parsing the DONUT_INSTANCE structure,…

Simple decrypter for Java AdWind, jRAT, jBifrost trojan

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…