
sift-kg
Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Scan files or process memory for CobaltStrike beacons and parse their configuration

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

Collecting & Hunting for IOCs with gusto and style

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Decrypt GlobalProtect configuration and cookie files.

Dump TeamViewer ID and password from memory. Works much better than other tools.

Tools for the Computer Incident Response Team :computer:

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Small toolkit for extracting information and dumping sensitive strings from Windows processes