
dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows

Forensics artefact collection tool for systems running Microsoft Windows

Digital Forensics Intelligence Framework


Generate bulk YARA rules from YAML input

Forensic evidence dossier for Operation Black Hole - Investigating fraudulent Falla app ecosystem (TRON blockchain, admin panel exposure,…

A free, open-source, and cross-platform iDevice management tool

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

The multi-platform memory acquisition tool.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…