
wireshark
Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.


Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Dshell is a network forensic analysis framework.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.


Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

FAT filesystems explore, extract, repair, and forensic tool

Linux Distro for Mobile Security, Malware Analysis, and Forensics