
AIL-framework
AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

Volatility plugin to extract X screenshots from a memory dump

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

A tool to use novel locations to extract metadata from Office documents.

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.