
Veto
Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Download and View Skype History Without Skype

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Program for determining types of files for Windows, Linux and MacOS.

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

pefile is a Python module to read and work with PE (Portable Executable) files

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Extract files from any kind of container formats

Windows tool for dumping malware PE files from memory back to disk for analysis.

Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

Log what files are accessed by any Linux process

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…