
Detect-It-Easy
Program for determining types of files for Windows, Linux and MacOS.

Program for determining types of files for Windows, Linux and MacOS.

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Collection of forensic tools

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

A free, open-source, and cross-platform iDevice management tool

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Investigation of CVE-2024-4577 exploitation and AsyncRAT deployment with DFIR artifacts, IoCs, and detection guidance.

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

A repository of sysmon configuration modules

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Automation and Scaling of Digital Forensics Tools

Regipy is an os independent python library for parsing offline registry hives

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Hunt down social media accounts by username across social networks