
gv_decryptor
Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

ThePhish: an automated phishing email analysis tool

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.


A utility for extracting cryptocurrency wallet data from wallet.dat files.

An OSINT / digital forensics tool built in Python

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A free, open-source, and cross-platform iDevice management tool

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

OS X Auditor is a free Mac OS X computer forensics tool

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.