
iLEAPP
Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

UNIX-like reverse engineering framework and command-line toolset.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Configuration Extractors for Malware

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

An OSINT investigation case mapping tool for organizing entities, relationships, evidence, and intelligence.

Open-source cybersecurity knowledge base with 400+ notes, labs, and cheat sheets covering offense, defense, cryptography, cloud, and forensics.

Records calls from a Trunked Radio System (P25 & SmartNet)

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.