
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Dshell is a network forensic analysis framework.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…


Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Malicious HTTP traffic explorer

Incident Response Forensic Framework

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Open source Android Forensics app and framework

Tool and framework for securely reading untrusted USB mass storage devices.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Labtainers: A Docker-based cyber lab framework

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…