Honeytoken tripwire for the Shai-Hulud npm worm.
Outils pour forensics
Incident response and evidence collection.
99 tools indexed
Collaborative forensic timeline analysis platform.
UAC
—Unix-like artifact collector.
UPX
—Ultimate Packer for eXecutables.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Memory forensics framework.
Open-source EDR for Windows.
Open-source XDR and SIEM.
Network protocol analyzer.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Yeti
—Open-source threat-intel platform.
Zeek
—Network analysis framework.
Malware analysis evasion test suite.
High-speed forensic feature extractor.
capa
—Identify executable capabilities.
.NET assembly debugger and editor.
Capture SSL/TLS plaintext with eBPF.
IDA Pro emulation scripting framework.
fq
—jq for binary formats.
Terminal-based malware triage toolkit written in Rust
macOS and iOS forensic artifact parser
SQL-powered endpoint visibility.