


Automated, Collection, and Enrichment Platform

Incident Response collection and processing scripts with automated reporting scripts

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A Software as a Service (SaaS) log collection framework.

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".


Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Externalize Java application access to protected resources as log messages.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Volatility Explorer Suit (volatility 3)

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

A powerful and flexible tool to apply active attacks for disrupting stegomalware