
iDescriptor
A free, open-source, and cross-platform iDevice management tool

A free, open-source, and cross-platform iDevice management tool

Program for determining types of files for Windows, Linux and MacOS.

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…


Collection of forensic tools

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

SQL powered operating system instrumentation, monitoring, and analytics.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

IoCs and YARA rules from Threatray's Threat Research

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Some setup scripts for security research tools.

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…