forensics

There are 1323 repositories under forensics topic.

  • sherlock

    sherlock-project/sherlock

    Hunt down social media accounts by username across social networks

    Language:Python63.4k1.1k1k7.3k
  • ImHex

    WerWolv/ImHex

    🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

    Language:C++47.6k4921.3k2.1k
  • radareorg/radare2

    UNIX-like reverse engineering framework and command-line toolset

    Language:C21.4k4928.5k3.1k
  • prowler

    prowler-cloud/prowler

    Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.

    Language:Python11.4k1251k1.7k
  • kubeshark

    kubeshark/kubeshark

    The API traffic analyzer for Kubernetes providing real-time K8s protocol-level visibility, capturing and monitoring all traffic and payloads going in, out and across containers, pods, nodes and clusters. Inspired by Wireshark, purposely built for Kubernetes

    Language:Go11.3k71334484
  • mvt-project/mvt

    MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

    Language:Python11k2603271.1k
  • rmusser01/Infosec_Reference

    An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

    Language:CSS5.7k264171.2k
  • Hack-with-Github/Free-Security-eBooks

    Free Security and Hacking eBooks

  • toolswatch/blackhat-arsenal-tools

    Official Black Hat Arsenal Security Tools Repository

  • jekil/awesome-hacking

    Awesome hacking is an awesome collection of hacking tools.

    Language:Python3.2k1449580
  • WithSecureLabs/chainsaw

    Rapidly Search and Hunt through Windows Forensic Artefacts

    Language:Rust3.1k56111274
  • decalage2/oletools

    oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.

    Language:Python3k100653568
  • volatilityfoundation/volatility3

    Volatility 3.0 development

    Language:Python3k58684496
  • sleuthkit/sleuthkit

    The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

    Language:C++2.8k179633626
  • timesketch

    google/timesketch

    Collaborative forensic timeline analysis

    Language:Python2.7k1331.4k603
  • sleuthkit/autopsy

    Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.

    Language:Java2.6k129623608
  • Yamato-Security/hayabusa

    Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

    Language:Rust2.5k41729216
  • dreddsa5dies/goHackTools

    Hacker tools on Go (Golang)

    Language:Go2.2k927379
  • danieldurnea/FBI-tools

    🕵️ OSINT Tools for gathering information and actions forensics 🕵️

  • log2timeline/plaso

    Super timeline all the things

    Language:Python1.8k912.1k367
  • Digital-Forensics-Guide

    mikeroyal/Digital-Forensics-Guide

    Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

    Language:Python1.8k325216
  • frankwxu/digital-forensics-lab

    Free hands-on digital forensics labs for students and faculty

    Language:Jupyter Notebook1.8k7214395
  • simsong/tcpflow

    TCP/IP packet demultiplexer. Download from:

    Language:C++1.7k80181241
  • Srinivas11789/PcapXray

    :snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction

    Language:Python1.7k7623281
  • MemLabs

    stuxnet999/MemLabs

    Educational, CTF-styled labs for individuals interested in Memory Forensics

    Language:Shell1.7k473212
  • AmnestyTech/investigations

    Indicators of Compromise from Amnesty International's cyber investigations

    Language:Python1.6k11718177
  • RecoverPy

    PabloLec/RecoverPy

    Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

    Language:Python1.5k142476
  • andriller

    den4uk/andriller

    📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.

    Language:Python1.4k4949221
  • cecio/USBvalve

    Expose USB activity on the fly

    Language:C1.3k255146
  • ForensicsTools

    mesquidar/ForensicsTools

    A list of free and open forensics analysis tools and other resources

  • usbrip

    snovvcrash/usbrip

    Tracking history of USB events on GNU/Linux

    Language:Python1.2k3122112
  • hindsight

    obsidianforensics/hindsight

    Web browser forensics for Google Chrome/Chromium

    Language:Python1.1k6499150
  • hackdroid

    thehackingsage/hackdroid

    Security Apps for Android

  • tclahr/uac

    UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

    Language:Shell9272665143
  • mozillazg/ptcpdump

    Process-aware, eBPF-based tcpdump

    Language:C91076850
  • ydkhatri/mac_apt

    macOS (& ios) Artifact Parsing Tool

    Language:Python8254480106