
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A tool for studying JavaScript malware.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Static analysis of malicious Python code

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…


PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Defense Against the Shai-Hulud Supply Chain Attack

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool