MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
Cybersecurity research results. Simple C/C++ and Python implementations
MESH enables remote wireless debugging for Android, providing mobile forensics & network monitoring over an encrypted, censorship-resistant …
Parses $MFT from NTFS file systems
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
Microsoft Sentinel SOC Operations
Mimicry is a dynamic deception tool that actively deceives an attacker during exploitation and post-exploitation.
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and sec…
Django application that performs SAST and Malware Analysis for Android APKs
ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.
Zero-dependency Linux memory forensics PoC — leverages kernel-embedded BTF and kallsyms for type-aware memory analysis without external debu…
Linux Incident Response Reporting
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
Malware repository component for samples & static configuration with REST API interface.
It's a hardware emulator + OS process simulator implemented in pure rust.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Linker/Compiler/Tool detector for Windows, Linux and MacOS.
Netdis is an open-source binary analysis tool powered by Ghidra. Upload files for disassembly, decompilation, control flow graphs and more, …
Network Forensics CLI utility that performs Network Scanning, OSINT, and Attack Detection
Network forensics analysis tool (NFAT) that captures packets and parses them to reconstruct transmitted files, certificates, images, and cre…
A lightweight tool to score network traffic and flag anomalies