
ptcpdump
eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A centralized and enhanced memory analysis platform

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

Redirect All Traffic Through Tor Network For Kali Linux

the ps utility, with an eBPF twist and container context

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.