
plaso
Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Documentation and scripts to properly enable Windows event logs.

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

Blue Team detection lab created with Terraform and Ansible in Azure.

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

Audit Preference Pane and Log Reader for OS X

PowerShell script that automates the WinRE mitigation workflow for CVE-2026-45585, with verification steps and conditional commit to avoid…

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Форензика после CVE-2026-41940 (cPanel/WHM) — bash-скрипт и чек-лист

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Distributed & real time digital forensics at the speed of the cloud

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.