
TCPViewer
The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project



Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

This repository contains a list of new remediation scripts.

Forensics artefact collection tool for systems running Microsoft Windows

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

This is the development tree. Production downloads are at:

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

An OSINT / digital forensics tool built in Python

Cortex: a Powerful Observable Analysis and Active Response Engine