
easy_triage
Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

Tool to scan for RouterOS (Mikrotik) forensic artifacts and vulnerabilities.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…


Cortex: a Powerful Observable Analysis and Active Response Engine

An OSINT / digital forensics tool built in Python

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

E-Mail Header Analyzer

GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat…

Forensics artefact collection tool for systems running Microsoft Windows