
swap_digger
Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Script for automating Linux memory capture and analysis

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Linux Distro for Mobile Security, Malware Analysis, and Forensics

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

An open source script to perform malware static analysis on Portable Executable

psad: Intrusion Detection and Log Analysis with iptables

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

A malware analysis and classification tool.

A utility for playing with cryptography, geared towards ransomware analysis.

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Collection of scripts for malware analysis, deobfuscation, and configuration extraction. Supports static analysis, unpacking, shellcode conversion,…