
PAGASUS-PRO
Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

Dshell is a network forensic analysis framework.

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

Event Trace Log file parser in pure Python

Demonstrates exploitation of CVE-2024-4577, a PHP CGI RCE on Windows, including attack steps, reverse shell deployment, and ransomware simulation…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Log what files are accessed by any Linux process

A wireshark plugin to instrument ETW

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.