Showing 36 of 193 projects
Recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
A Ruby framework for automated malware and botnet analysis using sandboxed virtual machines and network traffic dissection.
A Python script that uses Volatility to analyze malware memory footprints by comparing Windows memory images before and after infection.
A scripting framework for standardizing and automating Windows live forensic artifact acquisition using common utilities.
A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.
A simple, self-contained modular host-based IOC scanner built around the YARA pattern matching engine.
An Active Defense PowerShell framework for detecting and responding to phishing attacks in Office 365 environments.
A command-line tool for parsing, searching, and analyzing Windows Registry hives with batch processing and forensic capabilities.
A live forensics tool for Linux that collects system artifacts and logs them to CSV files for compromise detection.
A curated list of security card games and tabletop exercises for training and discussion.
A framework for analyzing and defending against supply chain attacks targeting Software Development Lifecycle infrastructure.
An autonomous open-source security agent for Linux that detects, scores, and automatically responds to threats using eBPF, AI, and collaborative defense.
An open-source malware analysis pipeline system that automates sample collection, processing, and JSON-based artifact storage.
A unified console for digital forensics and incident response built on the Viper Framework.
A PowerShell-based live response and forensic collection tool for targeted incident response on Windows systems.
A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.
Outlook add-in that enables users to report suspicious emails to security teams with one click.
A tool to quickly gather forensic artifacts from disk images or live systems into lightweight containers for digital forensic triage.
A modular Python tool that collects threat intelligence from multiple sources for files identified by their hash.
An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.
A command-line tool for digital forensics that checks file MD5 hashes against the NSRL Reference Data Set to identify known software files.
A PowerShell tool for auditing and configuring Windows event log settings to improve security visibility and detection capabilities.
A modular malware and IOC ingestion framework that collects, enriches, and exports threat intelligence from multiple feeds.
A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.
A toolkit for analyzing credential phishing sites by automating screenshot capture, file scraping, form interaction, and PDF URL extraction.
A tool for Exchange administrators to detect malicious client-side rules, VBScript forms, and custom homepages used in attacks.
A knowledge base documenting digital forensics artifacts to help investigators understand evidence sources and their forensic significance.
Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
A security incident response card game that trains defenders through fictional scenarios and activity-based gameplay.
A Heroku-based web honeypot for creating and monitoring fake HTTP endpoints (honeytokens) to detect attackers and malicious activity.
A modular web application honeypot framework written in Go and Gin for detecting web attacks through deceptive applications.
A memory forensics helper that automates initial data extraction from Windows memory images using Volatility.
A pure Python parser for classic Windows Event Log (.evt) files, enabling forensic analysis and log extraction.
A Volatility-based script for memory forensics that runs plugins, creates timelines, and scans for malware using YARA, ClamAV, and VirusTotal.
A forensic tool for remote acquisition, triage, and analysis of block devices via iSCSI protocol.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.