
velociraptor
Endpoint visibility and collection tool using VQL queries for host-based state information gathering, incident response triage, and forensic artifact…

Endpoint visibility and collection tool using VQL queries for host-based state information gathering, incident response triage, and forensic artifact…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Open-source digital forensic platform for processing and analyzing seized evidence. Supports disk images, file carving, hash analysis, OCR, audio…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Curated collection of recipes for DFIR, malware deobfuscation, and data transformation, with regex patterns, decoding workflows, and incident…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

A tool for forensic file system reconstruction.

Windows toolkit that installs and configures a comprehensive suite of digital forensics and incident response tools, integrating them into the system…

Unified digital forensics & incident response framework for parsing disk images, file systems, and OS artifacts across Windows, Linux, and ESXi…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

SANS DFIR forensic workstation distribution with pre-configured tools for memory analysis, disk forensics, timeline analysis, and incident response,…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Cross-platform hex editor for large files and disks, supporting binary data inspection, disk editing, and memory analysis for forensic and reverse…

Python tool to parse and analyze NTFS Master File Table (MFT) data, extracting file metadata, timestamps, and attributes for digital forensics and…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…