
rizin
UNIX-like reverse engineering framework and command-line toolset.

UNIX-like reverse engineering framework and command-line toolset.

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…


Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Library to access the Windows Shell Item format

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.


The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format