
ALEAPP
Android Logs Events And Protobuf Parser

Android Logs Events And Protobuf Parser

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Incident Response Documentation Platform

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

This repository contains a list of new remediation scripts.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

Detection-first incident-response toolkit for Zimbra administrators investigating CVE-2026-73570. Searches logs for exploit indicators, examines…

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)

DFIR forensics companion server + capture extension

Automate stopping bad bots from accessing your server