
packetsifterTool
PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Finding secrets in kernel and user memory

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Free educational courses in cybersecurity, reverse engineering, malware analysis, and programming designed to expand access, build practical skills,…

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A canary designed to minimize the impact from certain Ransomware actors

Python toolkit for malware analysis, designed to inspect suspicious files and extract indicators of compromise for security investigations.

A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282,…

Automate the creation of a lab environment complete with security tooling and logging best practices

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Collection of forensic tools