
forensictools
Collection of forensic tools

Collection of forensic tools

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Curated collection of indicators of compromise extracted from real-world malware investigations, including hashes, domains, and IPs for threat…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Repository of attack and defensive information for Business Email Compromise investigations

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Collection of private Yara rules.

Awesome list of keywords and artifacts for Threat Hunting sessions

A curated collection of DFIR skills and workflows for InfoSec practitioners.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices