
Zirconium
Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

A GUI and CLI tool for removing bloat from executables

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

A tool for mapping cyber crime

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Windows Analysis and Research Toolkit

Digital Forensics Intelligence Framework

Tool for searching pdfs withthin google and extracting pdf metadata

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…