
Disk-Arbitrator
A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Python tool for decrypting W32/Phase modules

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Windows link file (shortcuts) examiner

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates…

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

NeuroCore is a native macOS application that visualizes the internal structure of binary files using a Hilbert Curve mapping and Shannon Entropy…

Created to help detect IOCs for CVE-2022-21894: The BlackLotus campaign

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

A utility for extracting cryptocurrency wallet data from wallet.dat files.

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

WhatsApp Forensic Tool

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.