
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

OpenStego is a steganography application that provides two functionalities: a) Data Hiding: It can hide any data within an image file. b)…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Python implementation of the CaRT library for (un)inerting files.

Artifact collection tool for *nix systems

Recognizing the most likely APT groups responsible for an incident

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders


🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

A small utility to translate NTDS.dit files to SQLite format.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…