
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Volatility 3 ported to Rust. Same output, much faster.

ESF modular ingestion tool for development and research.

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

UNIX-like reverse engineering framework and command-line toolset.


Evtx Log (xml) Browser

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

Digital Forensics Intelligence Framework

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Incident Response Forensic Framework

Process heap analysis framework - Windows/Linux - record type inference and forensics

Malicious HTTP traffic explorer

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…