
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…


This is the development tree. Production downloads are at:


Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Collection of forensic tools

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Android Connections Forensics

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…