
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Hunt down social media accounts by username across social networks

Program for determining types of files for Windows, Linux and MacOS.

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A free, open-source, and cross-platform iDevice management tool

Cortex: a Powerful Observable Analysis and Active Response Engine

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

E-Mail Header Analyzer


Defanged Indicator of Compromise (IOC) Extractor.

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…