
ShadowNet
ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Self-hosted incident response platform with ticket management, automated reaction playbooks, task tracking, and dashboards for streamlining alert…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

ThePhish: an automated phishing email analysis tool