
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

A free, open-source, and cross-platform iDevice management tool

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

The multi-platform memory acquisition tool.

Forensics artefact collection tool for systems running Microsoft Windows

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…


Generate bulk YARA rules from YAML input

Digital Forensics Intelligence Framework