
shaha
Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

Program for determining types of files for Windows, Linux and MacOS.

Forensic PDF analysis tool that extracts hidden text from redacted documents, with batch processing and OCR capabilities for recovering obscured…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Read-only, forensically sound Android device acquisition tool with lockscreen cracking (pattern, PIN, password), app data decoding, WhatsApp crypt…

Filesystem monitor tool for Linux/Android iOS/macOS

Portable forensic acquisition tool for Android devices that extracts SMS, APKs, system logs, and process lists to identify spyware and compromise…

A GUI and CLI tool for removing bloat from executables

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Forensic tool to extract and analyze SQLite databases from rooted Android devices, generating structured XML reports for digital investigations.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Zero-dependency Python tool for binary visualization and forensics. Transforms binary data into interactive spectral maps to identify file…

GUI-based memory forensics tool for Volatility 2, enabling process/PE/handle inspection, file extraction, registry view, MFT analysis, and suspicious…

Python tool and library to help analyze files during malware triage and analysis.

Binary and Directory tree comparison tool using Fuzzy Hashing

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…