
FACT
Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

FAT filesystems explore, extract, repair, and forensic tool

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Linux Distro for Mobile Security, Malware Analysis, and Forensics

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

Incident Response & Digital Forensics Debugging Extension

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Python tool and library to help analyze files during malware triage and analysis.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865