
theZoo
Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Incarcero is a tool that creates Virtual Machines (VMs) preconfigured with malware analysis tools and security settings tailored for malware analysis…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

My musings with PowerShell

pefile is a Python module to read and work with PE (Portable Executable) files

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Portable Executable reversing tool with a friendly GUI

Collection of steganography tools - helps with CTF challenges