Select a tag to browse associated projects and drill deeper into the tag cloud.
Bro is an open-source, Unix-based Network Intrusion Detection System (NIDS) that passively monitors network traffic and looks for suspicious activity. Bro detects intrusions by first parsing network traffic to extract its application-level semantics and then executing event-oriented analyzers that ... [More]
Hachoir is a library written in Python which allows to see and edit a binary file (or any binary stream) field per field. A field is the most basic information: a number, a string of characters, a flag (yes/no), etc. Only supported formats can be opened, it's not a magic tool. It can be used to ... [More]
A simple but powerful tool with a flexible module system which will help you in your digital forensics works, including file recovery due to error or crash, evidence research and analysis, etc. Digital Forensics Framework (DFF) provides a robust architecture and some handy modules.
AlienVault Open Source SIM aims to be the all-in-one security solution for enterprise needs, featuring: Low level real-time detection of known threats and unknown abnormal activity Network, host and policies Audit Network behavior analysis and profiling Log management Intelligence to improve the ... [More]
PCGUI is a frontend to handle packet captures. Its aim is for Network Security Analysts who wants to have a non-commercial cheap storage for doing Network Forensics. It can uses daemonlogger/tcpdump/sancp for packet capturing and cxtracker for connection profiling. daemonlogger/tcpdump/sancp ... [More]
LibForensics is a library for developing digital forensics applications. Currently it is developed in pure Python. After a majority of the code has been developed and stabilized, the bottlenecks will likely be converted into C-based modules. I'm looking for people to use and test the ... [More]
The Volatility Framework is a completely open collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated ... [More]
VFAE is windows based tool written in C++ that extracts files with a known location from VMDK images running the Windows operating system. The tool utilizes the VDDK (Virtual Disk Development Kit) API for the heavy lifting such as mounting, opening, and reading the VMDK selected. When vfae.exe is ... [More]
iPhone Backup Analyzer is an utility designed to allow the user to simply browse through the contents of the backup folder of an iPhone (or any other iOS device). Read configuration files, browse archives and lurk into databases, and so on... Provides a plugin framework to develop viewers for ... [More]