
factual-rules-generator
Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A python tool that will extract exif data from picture with two methods

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Dump TeamViewer ID and password from memory. Works much better than other tools.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Imago is a python tool that extract digital evidences from images.

A simple, reliable and reasonably fast network capture analyzer.

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

A tool to use novel locations to extract metadata from Office documents.

Malware analysis from the domain goxlr.net

Small toolkit for extracting information and dumping sensitive strings from Windows processes