
OSXAuditor
OS X Auditor is a free Mac OS X computer forensics tool

OS X Auditor is a free Mac OS X computer forensics tool

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

Extracts KeePass master passwords from memory dumps of unlocked databases, outputting potential characters by position, a passphrase, and a…

Forensics artefact collection tool for systems running Microsoft Windows

Automated, Collection, and Enrichment Platform

ESF modular ingestion tool for development and research.

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Interactive DFIR walkthrough of CVE-2026-31431 (Copy Fail) - from SIEM alert to confirmed verdict. Real Volatility 3 commands, verified methodology.

privacy-first, open-source and free idevice management tool written in Rust and Qt