
irflow-timeline
DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

The Multiplatform Linux Sandbox

A network packet forensics tool for SSH

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Wireshark RDP resources

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Powershell module for VMWare vSphere forensics

Pcap importer for Burp

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

NetworkAssessment: Network Compromise Assessment Tool