
volatility3
Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

linux security checks

Automate the creation of a lab environment complete with security tooling and logging best practices

Production-ready detection & response queries for osquery

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…


Records calls from a Trunked Radio System (P25 & SmartNet)

Direct Memory Access (DMA) Attack Software

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Filesystem monitor tool for Linux/Android iOS/macOS

Log what files are accessed by any Linux process


A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Program for determining types of files for Windows, Linux and MacOS.