Category: Forensics

FSEventsParser

FSEventsParser: Parser for OSX/iOS FSEvents Logs

FSEvents files are written to disk by macOS APIs and contain historical records of file system activity that occurred for a particular volume. They can be found on devices running macOS and devices that...

Analysis of Logs

PAL: Performance Analysis of Logs tool

Performance Analysis of Logs (PAL) Tool Ever have a performance problem, but don’t know what performance counters to collect or how to analyze them? The PAL (Performance Analysis of Logs) tool is a powerful...

Altprobe

altprobe v1.0.2 releases: automation, continuous monitoring, orchestration, threat detection, and response

Altprobe The repository includes Alertflex collector and installation scripts for security sensors (Suricata NIDS, Wazuh HIDS, Falco CRS). Alertflex project is a cybersecurity solution for automation, continuous monitoring, orchestration, threat detection, and response. Alertflex...

mac_apt

mac_apt v1.5.8-dev releases: macOS Artifact Parsing Tool

mac_apt macOS Artifact Parsing Tool mac_apt is a DFIR tool to process Mac computer full disk images and extract data/metadata useful for forensic investigation. It is a python based framework, which has plugins to...

gimmecredz

gimmecredz: quickly dump all credz

Objective This tool can help pentesters to quickly dump all credz from known location, such as .bash_history, config files, wordpress credentials, and so on… This is not a hacking tool, just a collection of...

ManageEngine strelka

Strelka: real-time file scanning system

Strelka Strelka is a real-time file scanning system used for threat hunting, threat detection, and incident response. Based on the design established by Lockheed Martin’s Laika BOSS and similar projects (see: related projects), Strelka’s purpose is to...