
systeminformer
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Digital Forensics Intelligence Framework

Best-practice Linux Auditd rule set with 14,956 MITRE ATT&CK-mapped rules, Ansible deployment role, and lint/test tooling for security monitoring and…

Automate the creation of a lab environment complete with security tooling and logging best practices

OS X Auditor is a free Mac OS X computer forensics tool

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Documentation and scripts to properly enable Windows event logs.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Incident Response Forensic Framework

Production-ready detection & response queries for osquery

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.