#forensic

rekall
rekall

Rekall Memory Forensic Framework.

Velociraptor
Velociraptor

Endpoint visibility and collection tool.

mvt
mvt

Helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

volatility
volatility

The volatile memory extraction framework.

Tool capa
Tool capa

The FLARE team's open-source tool to identify capabilities in executable files.

radare2
radare2

UNIX-like reverse engineering framework and command-line toolset.

NetworkMiner
NetworkMiner

Network forensic analysis tool for Windows.