
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


A binary and file access authorization system for macOS.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Library and tools to access the Volume Shadow Snapshot (VSS) format

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

eBPF-powered runtime security sensor for CI/CD pipelines. Detects supply-chain attacks, logs process ancestry and file access, and provides forensic…

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Extensible MacOS system telemetry generator.

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…