Skip to content
Malware Analysis
Build Virtual Machine
Static Analysis
BinText
Strings for Linux
Strings for Windows
PEView
PEiD
KDiff 3
HashMyFiles
PEStudio
TRiD
UPX Unpacker
CFF Explorer
ExeInfo
SSDEEP
Dynamic Analysis
ApateDNS
DriverView
FakeNet
GMER
RegShot
MiTec Registry
Malzilla
Ring3 API Hooker
SSDT View
Wireshark
tshark
Sysinternals
ProcDOT
Reverse Engineering
IDA
Uncompyle
Immunity Debugger
x64dbg
OllyDbg
OllyDumpEx
Scylla x64-x86
APK Analysis
APKTool
ByteCodeViewer
jadx
Incident Response
Document Analysis
DocFileViewer
Peepdf
oledump
PDFStreamDumper
pdfparser
Pdfid
MalHost-Setup
DisView
RTFScan
OfficeMalScanner
Endpoint Analysis
Winprefetchview
LNK Analyzer
GKape
Kape
arp cache
netstat
tasklist
PacketWhisper
routeprint
net session
HashMyFiles
KDiff 3
YaraGen
YARA
Powershell
wmic
Sysinternals
BrowsingHistory
BLUESPAWN
Bruteshark
IOC Editor by FireEye
Redline by FireEye
Windows Live Response
THOR
LOKI
PSDecode
Eventlog Analysis
Advance log analysis
Baseline
DeepBlue CLI
Get-EventLog Hunt
Get-WinEvent Timeline
Get-WinEvent Hunt
Chainsaw
Hayabusa
Velociraptor
Custom Artifact
Shell Feature
Virtual File System
Velociraptor Hunt
Velociraptor Linux
Velociraptor Windows
Veloc WinMemCap
Digital Forensics
EZTools by EZimmerman
RegRipper by HCarvey
RegRipper3.0
FireEye
IOC Editor by FireEye
Memoryze
Redline by FireEye
Memory Acquisition
AccessData FTK
Belkasoft RamCapture
Dumpit
Magnet RAM Capture
Memoryze MemoryDD
Veloc WinMemCap
WinPmem
OSForensics
MemProcFS
Volatility
BulkExtractor
File Carving Photorec
Comae Hibr2bin
Timeline
Mactime
Volatility timeliner
log2timeline
The Sleuth Kit
TSK – fls
TSK – fsstat
TSK – icat
TSK – ils
Arsenal Image Mounter
Nirlauncher
fred
ewfinfo
vshadowmount
Autopsy Forensics
PhotoRec
Volatility3
Threat Hunting
MITRE ATT&CK
MITRE ATT&CK USAGE
Blog
EHMCrackTheCase
Latest News
Buy me a Coffee
Blogs you might like