
scripts
Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

A cross platform parser for Apple UnifiedLogs!


APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Log what files are accessed by any Linux process

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Event Trace Log file parser in pure Python

End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190