


Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.



Kirjuri is a web application for managing cases and physical forensic evidence items.

Hunt down social media accounts by username across social networks

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

ThePhish: an automated phishing email analysis tool

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…


Scan files or process memory for CobaltStrike beacons and parse their configuration

E-Mail Header Analyzer

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Regipy is an os independent python library for parsing offline registry hives

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…