
volatility
An advanced memory forensics framework

An advanced memory forensics framework


UNIX-like reverse engineering framework and command-line toolset.

Dshell is a network forensic analysis framework.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Malicious HTTP traffic explorer

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Open source Android Forensics app and framework

Tool and framework for securely reading untrusted USB mass storage devices.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…