
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865



Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders


Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

Step-by-step SOC analyst walkthrough for investigating and remediating CVE-2024-3400 (PAN-OS command injection). Covers detection, log analysis,…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…