
Aurora-Incident-Response
Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

A portable C# utility for enumerating local and remote windows sessions

Bash tool used for proactive detection of malicious activity on macOS systems.

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

privacy-first, open-source and free idevice management tool written in Rust and Qt

Download and View Skype History Without Skype

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Imago is a python tool that extract digital evidences from images.