Triage automation tool
☆23Aug 19, 2026Updated last month
Alternatives and similar repositories for triager
Users that are interested in triager are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆22Apr 1, 2026Updated 5 months ago
- Browse Windows Recycle Bin from E01 forensic images with Explorer-style interface. Parse $I/$R artifacts, view deleted files in original …☆18Dec 16, 2025Updated 9 months ago
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18Aug 26, 2026Updated 3 weeks ago
- Quick ESXi Log Parser☆33Jul 21, 2026Updated last month
- ☆70Jan 8, 2026Updated 8 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A GUI tool used to parse Sysmon log and display as process tree☆18Mar 21, 2026Updated 5 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- The most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl)…☆31Jul 28, 2026Updated last month
- Neural network RDP cache reconstruction tool☆34May 21, 2026Updated 3 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆17Jul 6, 2026Updated 2 months ago
- A lightweight tool to view, search and analyze registry hives☆20Aug 13, 2026Updated last month
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆52Updated this week
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 8 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆39Aug 7, 2026Updated last month
- A tool for fetching DFIR and other GitHub tools.☆30Updated this week
- Dissectify — macOS Forensic Analysis Toolkit. Collection health validation, 61 artifact parsers, XLSX export, and Velociraptor collector …☆52Aug 17, 2026Updated last month
- Forensic analysis of already-acquired WhatsApp Android databases - browse every chat exactly like the WhatsApp home screen, plus 30 foren…☆55May 9, 2026Updated 4 months ago
- Tools and scripts to deploy and manage OpenRelik instances☆17Mar 23, 2026Updated 5 months ago
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- ☆24Sep 7, 2026Updated last week
- Single-file desktop GUI for searching, browsing, and analyzing SQLite databases. Python + tkinter. No install required.☆25Apr 25, 2026Updated 4 months ago
- An example ISMS created with Claude for a fictious organisation.☆21Apr 3, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆35Jun 5, 2026Updated 3 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆39May 22, 2026Updated 3 months ago
- Just a vault template to help someone on the certificate.☆23Sep 3, 2025Updated last year
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆18Jan 17, 2026Updated 8 months ago
- A Windows Event Log MCP☆53Aug 25, 2025Updated last year
- ☆30Feb 12, 2026Updated 7 months ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆56Feb 20, 2026Updated 6 months ago
- A CTI program management and production platform built around MISP☆38Updated this week
- Binary template for ReFS and LogFile for 010 Editor that parses, and decodes the internal structures of ReFS metadata and log records☆16Apr 1, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆35Mar 16, 2026Updated 6 months ago
- Regexplore is a Volatility plugin designed to mimic the functionality of the Registry Explorer plugins in EZsuite☆18Mar 31, 2023Updated 3 years ago
- Linux Memory Forensics Framework That Transforms Memory Dumps Into a Navigable Filesystem☆206Jul 4, 2026Updated 2 months ago
- A GeoIP lookup utility utilizing ipinfo.io services.☆30Aug 30, 2026Updated 2 weeks ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Sep 1, 2026Updated 2 weeks ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆335Feb 26, 2026Updated 6 months ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 10 years ago