
ParrotSec-Linux-Hardening-Project
Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…


Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Easy-to-use live forensics toolbox for Linux endpoints

Incident Response collection and processing scripts with automated reporting scripts

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Digital Forensics Intelligence Framework