
pftriage
Python tool and library to help analyze files during malware triage and analysis.

Python tool and library to help analyze files during malware triage and analysis.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

An open source script to perform malware static analysis on Portable Executable

Script to remove homoglyphs and zero-width characters to allow for safe distribution of documents from anonymous sources.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…


A network sniffer that logs all DNS server replies for use in a passive DNS setup

Malicious HTTP traffic explorer

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…


Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Automatically create YARA rules from malicious documents.

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…