
ics-forensics-tools
Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Volatility 3 ported to Rust. Same output, much faster.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.


An advanced memory forensics framework

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Automatic security alert response framework by AWS Serverless Application Model

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A Software as a Service (SaaS) log collection framework.

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

ESF modular ingestion tool for development and research.

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.