
awesome-incident-response
Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Live Hidden Camera is a library which record live video and audio from Android device without displaying a preview.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Easy-to-use live forensics toolbox for Linux endpoints

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

Digital Forensics Intelligence Framework

Vibe Reverse Engineer with IDA SQL: An interface for IDA in SQL via live virtual tables

Incident Response - Fast suspicious file finder

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…


Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.