
scalpel
File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Forensics artefact collection tool for systems running Microsoft Windows

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.

A GUI and CLI tool for removing bloat from executables

A ProcessMonitor visualization application written in rust.

Cloud incident response and threat hunting tool that exports Azure, Entra ID, M365, and Defender telemetry for post-incident investigation and log…

A small utility to translate NTDS.dit files to SQLite format.

DPAPI looting remotely and locally in Python

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Decrypt GlobalProtect configuration and cookie files.

Browser-based OSINT mapper for cyber crime: enriches IPs, domains, and emails via Shodan, Hudson Rock, and IPInfo; analyzes email headers/time deltas…

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

An OSINT / digital forensics tool built in Python

Inspect live Windows system internals: processes, services, network, kernel callbacks, SSDT, and per-process anomalies; detect hooks and rootkits…