
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…


PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…


Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Collection of forensic tools

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A flow-based network monitor with Deep Packet Inspection

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Zeek support for Community ID flow hashing.