
fatt
FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

Powershell module for VMWare vSphere forensics

A tool for processing a lot of pcaps using tshark

Pcap importer for Burp

Offline AI Security Assistant for Air-Gapped Pentesting

create cypher create statements for neo4j out of netstat files from multiple machines

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Zeek support for Community ID flow hashing.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)