
EventHorizon
Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

UNIX-like reverse engineering framework and command-line toolset

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Best Practice Auditd Configuration

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

A swiss-knife MCP server for analysing PCAP files

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252