
TuxResponse
Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…


A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Easy-to-use live forensics toolbox for Linux endpoints

volatility explorer (volatility 2)

Volatility plugin for extracts configuration data of known malware

A Windows kernel dump C++ parser library with Python 3 bindings.

Automagically extract forensic timeline from volatile memory dump