
plaso
Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Enumerate various traits from Windows processes as an aid to threat hunting

Python Decoders for Common Remote Access Trojans

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…


Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Crack ios Restriction PassCode in Python

Crack iOS Restriction Passcodes with Python

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Real-time, container-based file scanning at enterprise scale

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Tool to find metadata and hidden information in the documents.

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Artifact collection tool for *nix systems

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…