
grr
Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Lua plugin to extract data from Wireshark and convert it into MISP format

A tool to assist with network-based hunting for GRU's Drovorub malware c2

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files