
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Free hands-on digital forensics labs for students and faculty

Easy-to-use live forensics toolbox for Linux endpoints

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Hunt down social media accounts by username across social networks

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Program for determining types of files for Windows, Linux and MacOS.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Never ever ever use pixelation as a redaction technique

Dshell is a network forensic analysis framework.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Automate the creation of a lab environment complete with security tooling and logging best practices