
digital-forensics-lab
Free hands-on digital forensics labs for students and faculty

Free hands-on digital forensics labs for students and faculty

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A swiss-knife MCP server for analysing PCAP files

Writeup for the DEF CON 30 badge challenge

TryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Collection of forensic tools

Program for determining types of files for Windows, Linux and MacOS.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

Hunts out CobaltStrike beacons and logs operator command output