The Volatility Framework is a completely open collection of tools, implemented in Python, for the extraction of digital artifacts from volatile memory (RAM) samples.
Read more
The Linux Portal Site
The Volatility Framework is a completely open collection of tools, implemented in Python, for the extraction of digital artifacts from volatile memory (RAM) samples.
Read morerdd is a forensic copy program developed at and used by the Netherlands Forensic Institute (NFI). rdd is a file and device copying utility.
Read moreThe forensic imager contained in this package, guymager, was designed to support different image file formats, to be most user-friendly and to run fast.
Read moreSuricata is a threat detection engine, combining intrusion detection, intrusion prevention, network security monitoring and PCAP processing.
Read moreSnort is an open source network intrusion prevention and detection system utilizing a rule-driven language.
Read moreZeek (formerly known as Bro) is a powerful free and open source framework for network traffic analysis and security monitoring.
Read moreMaltrail is a malicious traffic detection system, utilizing publicly available (black)lists.
Read moreHostsblock is a POSIX-compatible script for Linux designed to take advantage of the HOSTS file to block malware.
Read morelibredefender is an antivirus program. Scanning is implemented with libclamav.
Read moreUnhide is a forensic tool to find hidden processes and TCP/UDP ports by rootkits / LKMs or by another hiding technique.
Read more