
MrHandler
SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Incident Response collection and processing scripts with automated reporting scripts

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Cortex: a Powerful Observable Analysis and Active Response Engine

A Windows kernel dump C++ parser library with Python 3 bindings.

Easy-to-use live forensics toolbox for Linux endpoints

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

Volatility plugin for extracts configuration data of known malware

Automagically extract forensic timeline from volatile memory dump

volatility explorer (volatility 2)

Detection Script for MongoBleed Exploitation

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Android Logs Events And Protobuf Parser

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…


A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.