Showing 36 of 76 projects
A libpcap-based package for extracting and analyzing network flow data in JSON format for security research and monitoring.
A multithreaded PDF password cracking utility with structured search builders, checkpoint/resume, and optimized performance.
Binary data analysis and visualization tool that converts raw bytes into interactive visual patterns for rapid insight.
A command-line forensics tool for tracking USB device connection history on GNU/Linux systems.
A Python-based DFIR framework for extracting forensic artifacts from macOS and iOS disk images or live systems.
A CLI tool and library to identify hash types, supporting 675+ hash formats with hashcat and John the Ripper references.
An open-source GPU-accelerated password cracking tool for BitLocker-encrypted storage devices using dictionary attacks.
A PowerShell module for reverse engineering that disassembles code, analyzes malware, parses memory structures, and inspects Windows internals.
A standalone Python tool for applying SIGMA detection rules to EVTX, Auditd, Sysmon for Linux, and other log formats.
A lightweight Bash script for scanning Linux/Unix/OSX systems for Indicators of Compromise (IOCs) without installation.
A scalable, modular object scanner and intrusion detection system that extracts, flags, and enriches files with metadata.
A curated collection of Event ID resources for digital forensics and incident response professionals.
A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.
A forensic tool for exploring offline Docker container filesystems and metadata from disk images.
A forensic tool for exploring offline Docker filesystems to analyze compromised containers.
A network fingerprinting standard that identifies SSH client and server implementations via MD5 hashes of algorithm sets.
A self-hosted incident response platform that automates alert handling and ticket management for security teams.
A Volatility plugin that extracts configuration data and decoded strings from known malware families in memory images.
A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.
A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.
A Linux packet crafting tool for generating attack signatures to test IDS/IPS and network security.
A command-line Python tool for malware analysis with hex viewing, disassembly, file format support, and plugin architecture.
A high-speed memory forensics tool for analyzing physical memory dumps to find/extract processes and hypervisors using virtual machine introspection.
A modular, recursive file scanning framework that extends Yara signatures to extract and analyze file objects for malware analysis and intelligence.
A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.
A Kubernetes operator that creates checkpoint snapshots of running pods for offline forensic analysis after security incidents.
An open-source SIEM system built with Python Django for log management, risk assessment, and asset tracking.
An advanced Apache logfile security analyzer for post-attack forensics, detecting web application attacks using multiple detection techniques.
Recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.
A simple, self-contained modular host-based IOC scanner built around the YARA pattern matching engine.
A CLI utility and Python library for parsing, filtering, and analyzing log files and other structured data.
A CLI utility and Python library for parsing, filtering, and analyzing log files and other structured data.
A Docker-based honeypot that creates disposable containers to capture and analyze attack attempts.
A PowerShell-based live response and forensic collection tool for targeted incident response on Windows systems.
A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.