
forensictools
Collection of forensic tools

Collection of forensic tools

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

Zeek support for Community ID flow hashing.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Easy automated vulnerability scanning, reporting and analysis

The Sigma command line interface based on pySigma

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Enhanced SSH client with TUI — manage connections, keys, and sessions

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Corelight or Zeek Elastic Common Schema Templates

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

pySigma OpenSearch backend

Chronicle parser for CORELIGHT and related information.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻