Skip to content

Discover

Find tools for your stack. Pick an audience — we handle the noise.

Discover picks for Forensics & Incident Response

See all tools in Forensics & Incident Response →

On Hacker News

Ranked by discussion

See all →
  1. Moloch

    Moloch is an open source, large scale IPv4 packet capturing (PCAP), indexing and database system. A simple web interface is provided for PCAP browsing, searching, and exporting. APIs are exposed that allow PCAP data and JSON-formatted session data to be downloaded directly. Simple security is implemented by using HTTPS and HTTP digest password support or by using apache in front. Moloch is not meant to replace IDS engines but instead work along side them to store and index all the network traffic in standard PCAP format, providing fast access. Moloch is built to be deployed across many systems and can scale to handle multiple gigabits/sec of traffic.

    2
  2. macOS Artifact Parsing Tool (mac_apt)

    macOS (& ios) Artifact Parsing Tool

    At Risk
    1
  3. AVML

    AVML - Acquire Volatile Memory for Linux

    Healthy
    0
  4. Hindsight

    Browser forensics tool for Google Chrome (and other Chromium-based browsers)

    Healthy
    0
  5. Timesketch

    Collaborative forensic timeline analysis

    Healthy
    0
  6. Rizin

    UNIX-like reverse engineering framework and command-line toolset.

    Healthy
    0
  7. Radare2

    UNIX-like reverse engineering framework and command-line toolset

    Healthy
  8. Volatility 3

    Volatility 3.0 development

    Mixed
  9. Plaso

    Super timeline all the things

    Mixed
  10. Velociraptor

    Digging Deeper....

    Healthy
  11. Forensic Artifacts

    Digital Forensics Artifact Repository

    Mixed
  12. NullSec LogReaper

    High-speed log analysis and forensics tool with multi-format parsing, pattern matching, timeline reconstruction and anomaly detection for incident response.

    At Risk

Beta — feedback welcome: [email protected]