
MacPersistenceChecker
macOS persistence mechanism scanner with code signature verification and timeline tracking.

macOS persistence mechanism scanner with code signature verification and timeline tracking.

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Hunts out CobaltStrike beacons and logs operator command output

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

KeePass 2.X dumper (CVE-2023-32784)

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Automagically extract forensic timeline from volatile memory dump

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

Forensics artefact collection tool for systems running Microsoft Windows

Automated forensic script hunting for cve-2019-19781