
cosa-nostra
Cosa Nostra, a FOSS graph based malware clusterization toolkit.

Cosa Nostra, a FOSS graph based malware clusterization toolkit.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A python script developed to process Windows memory images based on triage type.

Digital forensic acquisition tool for Windows based incident response.

Frida.re based RunPE (and MapViewOfSection) extraction tool

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A C# based tool for analysing malicious OneNote documents

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Tool for solving BPF filters and crafting packets based on these.

A Zeek STUN protocol analyzer based on Spicy.

An ArchLinux based distribution for penetration testers and security researchers.

frida-stalker based system call tracer on windows(x64).

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…


Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…