Category: Forensics

geoip-attack-map: Cyber security geoip attack map

Cyber Security GeoIP Attack Map Visualization This geoip attack map visualizer was developed to display network attacks on your organization in real time. The data server follows a syslog file,...

WMIMon: Tool to monitor WMI activity on Windows

WMIMon This command line tool allows to monitor WMI activity on Windows platform. If you don’t have Visual Studio to build it, you can download binaries from https://github.com/luctalpe/WMIMon/blob/master/Downloads/WMIMon_Binaries.zip Features It is...

squidmagic: analyze a web-based network traffic

squidmagic: analyze a web-based network traffic

squidmagic is a tool designed to analyze a web-based network traffic to detect central command and control (C&C) servers and Malicious site, using Squid proxy server and Spamhaus. Installation Usage...

Web Shell Detector: Find webshell on server

Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web...

Android process memory dump

[Collection] Android Forensics tools

Bandicoot is a Python toolbox to analyze mobile phone metadata. It provides a complete, easy-to-use environment for data-scientist to analyze mobile phone metadata. With only a few lines of code,...

Android Dirty Pipe

Android Arsenal – Static Analysis Tools

AmandroidAmandroid is a static analysis framework for Android apps.The Android platform is immensely popular. However, malicious or vulnerable applications have been reported to cause several security problems. Currently, there is...

sshhipot: High-interaction MitM SSH honeypot

SSHHiPot High-interaction SSH honeypot (ok, it’s really a logging ssh proxy). Still more or less a work-in-progress. Feel free to go install this repository if you’d like to try it....

Forensic Tools Recommended

The purpose of this post is to share some forensic tools for safe learning and to prohibit illegal use. 1, ChromeForensics A tool to perform automated forensic analysis of Chrome...