
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

OS X Auditor is a free Mac OS X computer forensics tool

A list of cyber-chef recipes and curated links


This is the development tree. Production downloads are at:

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Incident Response Forensic Framework

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.


Acquires the EBS disks of an AWS AMI you can launch, streaming snapshots via EBS direct APIs to a private S3 bucket with sha256 manifests and…


Python script for carving Bitlocker VMK keys

Digital Forensics Intelligence Framework

A forensic evidence collection & analysis toolkit for OS X