
rayhunter
Rust tool to detect cell site simulators on an orbic mobile hotspot

Rust tool to detect cell site simulators on an orbic mobile hotspot


Comprehensive analysis of CVE-2022-30190 (Follina MSDT vulnerability) with IOCs, detection rules for SIEMs/EDR, YARA signatures, mitigation scripts,…

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

Research tool for studying vulnerable cryptographic key generation (brainwallet, PRNG, milksad, LCG, xorshift)

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

OSINT tool researched and designed to hunt down IG handles

Local Linux binary analysis tool. Zero cloud. Zero root. See exactly what a binary does before you run it.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…