
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Regipy is an os independent python library for parsing offline registry hives

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Hunt down social media accounts by username across social networks

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Program for determining types of files for Windows, Linux and MacOS.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Dshell is a network forensic analysis framework.

Tools and Techniques for Blue Team / Incident Response

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

A free, open-source, and cross-platform iDevice management tool

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

A repository of sysmon configuration modules