Skip to content

Discover

Find tools for your stack. Pick an audience — we handle the noise.

Discover picks for Forensics & Incident Response

See all tools in Forensics & Incident Response →

On Hacker News

Ranked by discussion

See all →
  1. Moloch

    Moloch is an open source, large scale IPv4 packet capturing (PCAP), indexing and database system. A simple web interface is provided for PCAP browsing, searching, and exporting. APIs are exposed that allow PCAP data and JSON-formatted session data to be downloaded directly. Simple security is implemented by using HTTPS and HTTP digest password support or by using apache in front. Moloch is not meant to replace IDS engines but instead work along side them to store and index all the network traffic in standard PCAP format, providing fast access. Moloch is built to be deployed across many systems and can scale to handle multiple gigabits/sec of traffic.

    2
  2. Radare2

    UNIX-like reverse engineering framework and command-line toolset

    Healthy
    1
  3. AVML

    AVML - Acquire Volatile Memory for Linux

    Mixed
    0
  4. Plaso

    Super timeline all the things

    At Risk
    0
  5. grr

    GRR Rapid Response: remote live forensics for incident response

    At Risk
  6. Forensic Artifacts

    Digital Forensics Artifact Repository

    At Risk
  7. CAPA

    The FLARE team's open-source tool to identify capabilities in executable files.

    At Risk
  8. Flare

    A fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing.

    At Risk
  9. NullSec LogReaper

    High-speed log analysis and forensics tool with multi-format parsing, pattern matching, timeline reconstruction and anomaly detection for incident response.

    Mixed
  10. Splunk Attack Range

    A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

    At Risk
  11. Velociraptor

    Digging Deeper....

    At Risk
  12. UAC

    UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

    At Risk

Beta — feedback welcome: [email protected]