
whapa
Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

A repository of sysmon configuration modules

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

Incident Response & Digital Forensics Debugging Extension

Blue Team detection lab created with Terraform and Ansible in Azure.

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

A swiss-knife MCP server for analysing PCAP files


Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252