⭐️ A curated list of awesome forensic analysis tools and resources
-
Updated
Dec 8, 2024
⭐️ A curated list of awesome forensic analysis tools and resources
❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
WhatsApp Parser Toolset v1.59
A list of free and open forensics analysis tools and other resources
Collaborative Incident Response platform
Tools and packages that are used for countering forensic activities, including encryption, steganography, and anything that modify attributes. This all includes tools to work with anything in general that makes changes to a system for the purposes of hiding information.
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Avilla Forensics 3.0
WinDBG Anti-RootKit Extension
Awesome list of digital forensic tools
Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...
CLI tools for forensic investigation of Windows artifacts
Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!
A collection of tools for forensic analysis
Python script to decode common encoded PowerShell scripts
This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely u…
Forensic toolkit for iOS sysdiagnose feature
Add a description, image, and links to the forensic-analysis topic page so that developers can more easily learn about it.
To associate your repository with the forensic-analysis topic, visit your repo's landing page and select "manage topics."