
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Dshell is a network forensic analysis framework.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…


This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

An advanced memory forensics framework

Volatility 3 ported to Rust. Same output, much faster.

UNIX-like reverse engineering framework and command-line toolset.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Malicious HTTP traffic explorer

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Tool and framework for securely reading untrusted USB mass storage devices.

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…