cyberstars
cyberstars / purpose / forensics

Tools for forensics

Incident response and evidence collection.

99 tools indexed

Honeytoken tripwire for the Shai-Hulud npm worm.

MonitorSource codeEndpoints
PythonApache-2.0

Collaborative forensic timeline analysis platform.

AnalyzeEndpoints
PythonApache-2.0

UAC

Unix-like artifact collector.

AnalyzeMonitorEndpoints
ShellApache-2.0

UPX

Ultimate Packer for eXecutables.

AnalyzeBinaries
C++GPL-2.0

Zero-install cross-platform incident response and DFIR toolkit.

AnalyzeMonitorEndpoints
GoMIT

Endpoint visibility and DFIR.

MonitorAnalyzeEndpoints
GoAGPL-3.0

Memory forensics framework.

AnalyzeEndpointsBinaries
PythonVSL

Open-source EDR for Windows.

MonitorAnalyzeEndpoints
GoGPL-3.0

Open-source XDR and SIEM.

MonitorScanEndpointsCloud
CAGPL-3.0

Network protocol analyzer.

InterceptAnalyzeNetworksWireless
CGPL-2.0

YARA

Pattern matching for malware research.

AnalyzeMonitorBinariesEndpoints
CBSD-3-Clause

Community YARA rule repository.

MonitorAnalyzeBinariesEndpoints
YARAGPL-2.0

Yeti

Open-source threat-intel platform.

AutomateAnalyzeNetworksEndpoints
PythonApache-2.0

Zeek

Network analysis framework.

MonitorAnalyzeNetworks
C++BSD-3-Clause

Malware analysis evasion test suite.

AnalyzeBinaries
C++GPL-3.0

High-speed forensic feature extractor.

AnalyzeEndpointsBinaries
C++MIT

capa

Identify executable capabilities.

AnalyzeBinaries
PythonApache-2.0

.NET assembly debugger and editor.

AnalyzeBinaries
C#GPL-3.0

Capture SSL/TLS plaintext with eBPF.

InterceptAnalyzeNetworksEndpoints
CApache-2.0

IDA Pro emulation scripting framework.

AnalyzeBinaries
PythonApache-2.0

fq

jq for binary formats.

AnalyzeBinariesNetworks
GoMIT

Terminal-based malware triage toolkit written in Rust

AnalyzeScanBinaries
RustMIT

macOS and iOS forensic artifact parser

AnalyzeEndpoints
PythonMIT

SQL-powered endpoint visibility.

MonitorAnalyzeEndpoints
C++Apache-2.0