
rekall
Rekall Memory Forensic Framework

Re-play Security Events

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Current links from the OSINT Inception start-me project

Blue Team detection lab created with Terraform and Ansible in Azure.

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Kirjuri is a web application for managing cases and physical forensic evidence items.

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Generate bulk YARA rules from YAML input

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…