
peframe
PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

operative framework is a rust investigation OSINT framework, you can interact with multiple targets, execute multiple modules, create links with…

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Deep File Forensic. Create or manipulate Wordlists out of Text Documents (ex: for BruteForcing). Save it Line by Line as a Binary .BIN File or as a…

Step-by-step SOC incident response walkthrough for CVE-2024-24919 arbitrary file read on Check Point gateways, covering detection, analysis,…

Steganography Tool for JPG Images

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

Universal signature generation for any system function from all Windows Builds using Winbindex

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Tool to securely and efficiently wipe devices and partiitions for Linux

Rip Raw is a small tool to analyse the memory of compromised Linux systems.
