cyberstars
cyberstars / purpose / forensics

Tools for forensics

Incident response and evidence collection.

99 tools indexed

AVML

Acquire volatile memory on Linux.

AnalyzeEndpoints
RustMIT

Cross-platform forensic artifact collector in Rust

AnalyzeEndpoints
RustMIT

File triage and malware analysis pipeline.

AnalyzeAutomateBinariesEndpoints
PythonMIT

Digital forensics platform.

AnalyzeEndpointsBinaries
JavaApache-2.0

Cloud forensics for Azure / O365.

AnalyzeMonitorCloud
PowerShellGPL-3.0

Firmware analysis tool.

AnalyzeBinaries
RustMIT

Account search across 600+ networks.

ReconWeb apps
PythonMIT

User-mode x86_64 emulator for malware analysis.

AnalyzeBinaries
C#GPL-2.0

Java 8+ JAR and Android APK RE suite.

AnalyzeBinariesMobile apps
JavaApache-2.0

Malware sandbox + payload extraction.

AnalyzeBinaries
PythonGPL-3.0

CISA's DFIR tool.

AnalyzeScanEndpoints
PythonCustom

Tripwire tokens for free.

MonitorEndpointsNetworks
PythonMIT

Hunt across Windows event logs at speed.

AnalyzeMonitorEndpoints
RustGPL-3.0

Automatic cipher/encoding/hash cracker.

CrackAnalyzeBinaries
PythonMIT

Observable analysis engine for TheHive.

AnalyzeAutomateNetworksEndpoints
ScalaAGPL-3.0

GUI reverse engineering on Rizin.

AnalyzeBinaries
C++GPL-3.0

The cyber Swiss army knife.

AnalyzeAutomateWeb appsBinaries
JavaScriptApache-2.0

Python bytecode decompiler.

AnalyzeBinaries
C++GPL-3.0

Hunt PowerShell attacks in Windows logs.

AnalyzeMonitorEndpointsActive Directory
PowerShellBSD-3-Clause

Cross-platform file type identifier.

AnalyzeBinaries
C++MIT

Forensic artifact framework from Fox-IT.

AnalyzeEndpointsBinaries
PythonAGPL-3.0

Network forensic analysis framework.

AnalyzeNetworks
PythonCustom

Windows ETW provider browser and trace inspector.

AnalyzeMonitorEndpoints
C#GPL-3.0

FAME

Malware analysis automation.

AnalyzeAutomateBinaries
PythonGPL-3.0