
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Large-scale open-source network analysis and full packet capture system. Indexes PCAP traffic in standard format, providing fast search, browsing,…

Windows toolkit that installs and configures a comprehensive suite of digital forensics and incident response tools, integrating them into the system…

eBPF-based machine-history debugger for Linux that records process, file, network, memory, and block I/O metadata into SQLite for timeline, diff, and…

AI-powered network intrusion detection system (NIDS) with deep packet inspection, machine learning anomaly detection, protocol analysis, and network…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Perl-based forensic scanner for disk, memory, network, and mobile device analysis. Designed for incident response and digital evidence collection.

Linux crypto-miner detection, removal, and hardening toolkit. Detects hidden processes via hardware counters, blocks mining pools, removes…