kraken. Cross-platform Yara scanner written in Go
327targetedthreats. Collection of IOCs related to targeting of civil society
190pcqf. pcqf (PC Quick Forensics) helps quickly gathering forensic evidence from Windows, Mac, and Linux systems, in order to identify potential traces of compromise.
134ntap. Transparent network tap
123vxcage. REST API based malware repository (abandoned)
107virustotal. VirusTotal tools
92snoopdroid. (Abandoned) Extract packages from an Android device
53habu. Python static blog generator
42resist-the-internet. Leave no chance to Surveillance Capitalism and let this extension make decisions for you
29volatility. An advanced memory forensics framework
25stix2gen. Python
10is-lockdown. JavaScript
9kraken-docs.
6tldts. Library to work against complex domain names, subdomains and URIs.
5iOSbackup. A Pyhotn 3 class that reads and extracts files from a password-encrypted iOS backup created by iTunes on Mac and Windows. Compatible with iOS 13.
5threatactors. Parsable collaborative collection of threat actors
4mass_archive. A basic tool for pushing a web page to multiple archiving services at once.
3processing_websockets. A web socket library, including both server and client, for Processing
3urlx. Golang pkg for URL parsing and normalization
2snoopwatchd. Go
2oz. OZ: a sandboxing system targeting everyday workstation applications
2IRTF-HRPC. Files of IRTF HRPC research group
2html2text. Golang HTML to plaintext conversion library
2semiphemeral. Automatically delete your old tweets, except for the ones you want to keep
1libimobiledevice. A cross-platform protocol library to communicate with iOS devices
1misp-galaxy. Clusters and elements to attach to MISP events or attributes (like threat actors)
1pymobiledevice3. pymobiledevice fork with more recent coding standards and many more features
1jarm. Python
1iranthreats.github.io. HTML
1gopsutil. psutil for golang
1go-yara. Go bindings for YARA
1go-taskscheduler. Connect to Windows Task Scheduler 2.0 with Golang
1go-removal. Go
1