macosac. Forensic Artifact Collection Tool for macOS
121fjta. FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities.
112vss_carver. Carves and recreates VSS catalog and store from Windows disk image.
101ma2tl. macOS forensic timeline generator using the analysis result DBs of mac_apt
95norimaci. Norimaci is a simple and lightweight malware analysis sandbox for macOS
71bgiparser. A parsing tool for backgrounditems.btm
54DSStoreParser. macOS .DS_Store Parser
7linimagemounter. LinImageMounter is a Python tool designed to simplify the process of mounting disk images on Linux systems.
6libvmdk-Shift_JIS. Library and tools to access the VMware Virtual Disk (VMDK) format
3mac_apt. macOS (& ios) Artifact Parsing Tool
3cidre-vm. Software installation scripts for macOS systems that allows you to setup a Virtual Machine (VM) for reverse engineering macOS malware
2libvshadow-vss_carver. Library and tools to access the Volume Shadow Snapshot (VSS) format
2precompiled_libyal_libs. Pre-compiled libyal libraries
2FSEventsParser. Parser for OSX/iOS FSEvents Logs
2Mac_ISF. Volatility3 ISF for Mac Os memory forensic.
1CrackMapExec. A swiss army knife for pentesting networks
1lldbinit. A gdbinit clone for LLDB
1objective-see_Malware. macOS Malware Collection
1afro. File recovery for APFS
1sqlite-dissect. DC3 SQLite Dissect
1llios. Random stuff about lower level iOS
1Hibr2Bin. Comae Hibernation File Decompressor
1uac. UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
1LinuxMalwareSourceCode. This is a repository of the source code of various malware targeting the *nix (mostly Linux) operating systems.
1Mirai-Source-Code. Leaked Mirai Source Code for Research/IoC Development Purposes
1APT06202001. Applied Purple Teaming - Infrastructure, Threat Optics, and Continious Improvement - June 6, 2020
1volatility-plugins. Plugins I've written for Volatility
1LinuxForensics. Everything related to Linux Forensics
1macOS_FE. Tools for macOS Forensic Bootable media
1WindowsMalwareSourceCode. Collection of Source Code of Various Malware Targeting the Windows Platform
1KnockKnock. Enumerate persistently installed software
1macos_execute_from_memory. PoC of macho loading from memory
1flare-ida. IDA Pro utilities from FLARE team
1Malware-Analysis-Training. Retired beginner/intermediate malware analysis training materials from @pedramamini and @erocarrera.
1trochilus. A Fast & free Windows remote administration tool.
1