
refinery
Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Expose USB activity on the fly

machofile is a module to parse Mach-O binary files

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

An OSINT / digital forensics tool built in Python

PowerShellProfiler

Enumerate various traits from Windows processes as an aid to threat hunting

A tool to use novel locations to extract metadata from Office documents.

Fingerprint SSH clients and servers.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

Official repository for CTFTiny

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

This project is now part of @mitmproxy.