
pastokrapacefleciks
Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

A wireshark plugin to instrument ETW

Event Trace Log file parser in pure Python

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

This repository serves as a place for community created Targets and Modules for use with KAPE.

Mapping Corelight or Zeek data to Elastic Common Schema fields

A cross platform parser for Apple UnifiedLogs!

Corelight@Home script

Mapping Corelight or Zeek data to Elastic Common Schema logs

Scanner for CVE-2024-4040

A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282,…