
ACE
Automated, Collection, and Enrichment Platform

Automated, Collection, and Enrichment Platform

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Download and View Skype History Without Skype

Windows link file (shortcuts) examiner

Volatility plugin to extract X screenshots from a memory dump

IOC feed and analysis toolkit for EITest campaigns, featuring C2 data decryption, victim payload decoding, and sinkhole log processing for threat…

Automated forensic script hunting for cve-2019-19781

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

Reproduce DeFi hacked incidents using Foundry.

Tools and Techniques for Blue Team / Incident Response

You didn't think I'd go and leave the blue team out, right?

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

A centralized and enhanced memory analysis platform

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs