


Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Cortex: a Powerful Observable Analysis and Active Response Engine

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Artifact collection tool for *nix systems

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Defanged Indicator of Compromise (IOC) Extractor.

Forensics artefact collection tool for systems running Microsoft Windows

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️