top of page
shutterstock_1902760141.jpg

Tool Library

Welcome to My Cybersecurity Tool Library—an invaluable resource created to equip you with insights into a multitude of tools. My mission is to demystify these tools, providing clarity and understanding to aid your cybersecurity journey.

This page serves as a comprehensive guide, featuring a curated selection of tools that cover various aspects of cybersecurity. Whether you're a novice or an expert in the field, this library offers a wealth of information to assist you in comprehending and leveraging the capabilities of these tools effectively

KAPE

image.png

KAPE, crafted by Eric Zimmerman, stands as a powerful, free, and versatile triage collection and post-processing tool designed to streamline forensic data gathering.   (My Professional use)

Blog Link:

To Learn about this tool/Series of article : Click Me

Velociraptor

Exploring Velociraptor_ A Versatile Tool for Incident Response and Digital Forensics.jpg

Velociraptor is one such tool that stands out for its unique capabilities, making it an essential part of any forensic investigator or incident responder’s toolkit. Whether you're conducting a quick compromise assessment, performing a full-scale threat hunt across thousands of endpoints, or managing continuous monitoring of a network, Velociraptor can handle it all.

To learn about this tool/ Series of article:  Click Me

An All-in-One PowerShell Script

Boy in mask.jpg

I've tried to developed a PowerShell script designed to perform an analysis of system and collect information, covering everything from basic system information to intricate details. This script outputs the collected data in a clean HTML format, making it easy to review and act upon.

Streamlining Incident analysis: An All-in-One PowerShell Script

Click Here

Registry Keys and File Locations Captured by Script    : Click Me

CE SentinelOne Assistant

Browser forensic.jpg

The CE S1 Assistant is a web-based tool that does one thing well — it helps you write SentinelOne Deep Visibility queries faster. Describe what you're hunting, paste a threat report, or drop in IOCs directly, and get a ready-to-run query back. No documentation diving, no syntax headaches.

Meet the CE SentinelOne Assistant — I Built It for Myself, But You Can Try It Too    : Click Me

CE SentinelOne Assistant : New Features     : Click Me

Petra Security

image.png

Petra is an OAuth-based security app for Microsoft 365 that does one thing — and does it incredibly well: identity threat detection. Think of it as what Microsoft’s Entra P1/P2 should’ve been — except smarter, more accurate, and way less expensive.

Links for the courses             :  Click Me

Sentinel One

Sentinel One Chronicles_ Navigating a Cybersecurity Titan.jpg

One of My favorite Tool: Unlock the full potential of SentinelOne with this in-depth series of articles designed to elevate your expertise in threat detection, investigation, Incident response and forensic and much more

Links for the courses             :  Click Me

CarbonBlack

CarbonBlack Endpoint detection response..jpg

Unlock the full potential of Carbon Black with this in-depth series of articles designed to elevate your expertise.

Links for the courses             :  Click Me

Sublime Security (EDR For Email)

Sublime Security – The EDR of Email We Needed!.jpg

Sublime Security is an open, programmable email security platform designed to run detection logic and visibility across your cloud inboxes.

Links for the courses             :  Click Me

Dropzone AI

Is AI Coming for SOC Jobs_ A Real Talk + My First Look at Dropzone AI.jpg

Dropzone AI works like a tireless SOC analyst, turning noisy alerts into fast, accurate security insights..

Links for the courses             :  Click Me

Redline

image.png

RedLine is an advanced forensics tool designed to deeply analyze Windows systems for malicious activity. With its comprehensive suite of capabilities.

FireEye Redline: A Powerful Endpoint Investigation Tool

Click Here

Cyber Triage

image.png

Cyber triage collecting and analyzing endpoint data, it helps cybersecurity professionals quickly identify, prioritize, and respond to security incidents, enhancing overall incident management workflows.

Cyber Triage: Another Powerful Investigation tool

Click Here

Go Phish

image.png

GoPhish — a free, open-source phishing framework written in Go. It gives you a slick web dashboard where you can create email templates, build landing pages, manage target groups, launch campaigns, and watch results come in live.

I Built a Full GoPhish + Azure Phishing Simulation Platform — Here's Exactly How

Click Here

HayaBusa

image.png

In the realm of log analysis tools, Hayabusa stands out as an indispensable asset, particularly in deep investigations following initial analyses.

Blog Link

Hayabusa: A Powerful Log Analysis Tool for Forensics and Threat Hunting:  Click Here

Hayabusa.exe: Essential Commands for In-depth Log Analysis 

Click here

Log Parser

image.png

It supports parsing and analyzing log files from a wide range of sources such as Windows Event logs, IIS logs, CSV files, XML files, and more.

Microsoft's Log Parser 

Click Here

OS Forensics

image.png

This software allows professionals to delve into operating systems to gather evidence, uncover hidden data, and perform comprehensive forensic analysis.

OS Forensics by PassMark: A Game-Changer in Digital Forensics

Click Here

Chainsaw

image.png

Chainsaw is a command-line tool that provides a fast method of running Sigma rule detection logic over event log data to highlight suspicious entries. 

Blog Link:

Chainsaw: Streamlining Log Analysis for Enhanced Security Insights: Click here

Chainsaw.exe :- commands :  Click here

DensityScout

image.png

Specializing in the detection of common obfuscation techniques such as runtime packing and encryption,

Blog Link:

Unveiling Suspicious Files with DensityScout : Click here

 Thumbcache_viewer_64

thumbcache_viewer_64=.jpg

Thumbnail cache in Windows is an essential feature that helps speed up the display of folders by storing thumbnail images.

Blog Link:

Understanding and Managing Thumbnail Cache in Windows : Click here

Magnet Encrypted Disk Detector

Encrypted Disk Detector.jpg

(EDDv310) is a powerful tool designed to quickly and non-intrusively check for encrypted volumes on a system..

Blog Link:

Exploring Magnet Encrypted Disk Detector (EDDv310) : Click here

User Activity with LastActivityView

LastActivityView.jpg

LastActivityView is a free tool that collects and displays information about the recent activities on your Windows computer...

Blog Link:

Unveiling User Activity with LastActivityView by NirSoft : Click here

MFTECmd-MFTexplorer

MFTECmd-MFTexplorer_ A Forensic Analyst's Guide.jpg

When it comes to forensic tools, MFTECmd.exe is one of my go-to choices. It’s part of the KAPE suite and an incredibly efficient tool for parsing NTFS artifacts like $MFT, $J, $Boot, $SDS, and $I30

Blog Link:

MFTECmd-MFTexplorer: A Forensic Analyst's Guide : Click here

WinSearchDBAnalyzer / SQLite / SIDR

Unlocking Windows Search Indexing for Forensics_ A Deep Dive.jpg

These powerful tools for parsing the Windows Search Database. these tool effectively makes the contents of the Windows search index available for forensic investigation

Blog Link:

A Deep Dive into Windows Search Database Parsing (WinSearchDBAnalyzer / SQLite / SIDR) : Click here

Master Wireshark

Master Wireshark Like a Pro_ .jpg

I know you’ve probably come across tons of Wireshark articles already, but trust me—this one’s different. I’ve kept it real, practical, and straight from an investigator perspective. Give it a read, and you’ll see exactly what I mean. 

Blog Link:

Master Wireshark tool Like a Pro: – The Ultimate Packet Analysis Guide for Real-World Analysts : Click here

Arkime

image.png

Arkime (previously known as Moloch, and yes, you’ll still see that name floating around in some commands and docs) is an open-source tool designed specifically to capture, index, and analyze network traffic — at scale. 

Blog Link:

Why Arkime is a Game-Changer for Network Forensics  : Click here

Querying Like a Pro in Arkime :  Click Me

Registry Explorer

The Windows Registry_ The Black Box Flight Recorder of Your PC__edited.jpg

Registry Explorer isn't just a registry viewer. It's closer to a full forensic workstation for registry analysis. 

Blog Link:

The Registry Analyst's Toolkit: Choosing Your Weapon  : Click here

Volatility 3

image.png

It's a powerful toolset designed to extract digital artifacts from volatile memory (RAM) and perform in-depth forensic investigations. 

Unveiling Volatility 3: A Guide to Extracting Digital Artifacts:

Click Here

Microsoft-Extractor-Suite and Microsoft-Analyzer-Suite

Cloud Forensic.jpg

Microsoft-Extractor-Suite is an actively maintained PowerShell tool designed to streamline data collection from Microsoft environments, including Microsoft 365 and Azure."

Streamlining Cloud Log Analysis with Free Tools: Microsoft-Extractor-Suite and Microsoft-Analyzer-Suite :- Click Me

Memory Forensics Using Strings and Bstrings

Memory Forensics Using Strings and Bstrings_ A Comprehensive Guide.jpg

Two key tools frequently used in this process are Strings and Bstrings. While both help extract readable characters from memory dumps, they offer distinct features that make them suitable for different environments.. 

Memory Forensics Using Strings and Bstrings: A Comprehensive Guide:   Click Here

MemProcFS/MemProcFS Analyzer

Memory Process forensic _ Comprehensive Analysis Guide.jpg

MemProcFS is a powerful memory forensics tool that allows forensic investigators to mount raw memory images as a virtual file system. 

MemProcFS/MemProcFS Analyzer: Comprehensive Analysis

Guide: Click Here

NMAP

image.png

Nmap allows users to discover devices on a network, perform port scanning to determine which ports are open on target systems, and gather information about the services running on those ports.

Network Scanning with Nmap:

Click Here

Suricata

image.png

Suricata is an open-source Network Intrusion Detection System (NIDS), Network Security Monitoring (NSM), and Intrusion Prevention System (IPS) designed for real-time traffic analysis and security monitoring

Blog Link

Exploring Suricata: Part 1:  Click here

How to Download and Start Suricata Part 2Click here

Suricata Configuration Part 3: Click here

Suricata configurations Part 4 : Click here

CentralOps

image.png

CentralOps, a robust online suite of tools and services designed to provide a one-stop solution for gathering critical internet-related data

Unveiling the Power of CentralOps

Click here

Kansa-Master

image.png

One powerful tool that exemplifies this proactive stance is Kansa, a robust data collection framework designed for incident response and threat hunting.

Power of Kansa: A Comprehensive Guide to Incident Response and Threat Hunting:

Click me

Prefetch Analysis with PECmd and WinPrefetchView

image.png

Prefetching, a process optimizing system performance by loading data into memory before needed, generates valuable artifacts in the form of .pf files

Prefetch Analysis with PECmd and WinPrefetchView:

Click me

AppCompatCache tool for ShimCache Forensic Analysis

image.png

designed to detect and remediate program compatibility challenges that may arise when a program is launched.

Understanding AppCompatCache tool for ShimCache Forensic Analysis: Click me

Amcache.hve: A Forensic Artifact( AmcacheParser)

image.png

AmcacheParser is a tool developed by Eric Zimmerman that parses the Amcache.hve registry hive, a critical artifact in Windows forensic analysis

Mastering AmcacheParser and appcompatprocessor.py for Amcache.hiv Analysis: Click Me

Power of EvtxECmd

image.png

Eric Zimmerman's EvtxECmd emerges as a game-changer, offering not just a command-line parser but a comprehensive tool for transforming, filtering, and extracting critical information from Windows event logs

Unleashing the Power of EvtxECmd: Windows Event Log Analysis:

Click me

Mastering JLECmd

image.png

Jump Lists represent a dynamic feature engineered to empower users by granting them swift access to frequently or recently used items.

Blog Link:

Mastering JLECmd for Windows Jump List Forensics :- Click Me

SBECmd.exe or ShellBagsExplorer

5fb032_e9419fcf936c4b9598271183a268027f~mv2.png

Shell Bags are data structures within the Windows registry that track user window viewing preferences in Windows Explorer.

Blog Link:

Unlocking ShellBags Analysis with ShellBags Explorer (SBE) / SBECmd.exe :- Click Me

WinPmem

image.png

WinPmem is a robust memory acquisition tool designed specifically for Windows environments.

Unveiling System Secrets with WinPmem(memory acquisition tool):

Click me

RBCmd and $I_Parse

image.png

The recycle bin plays a significant role in forensic investigations on Windows filesystems, offering valuable insights into deleted files and user activities.

Analyzing Recycle Bin Metadata with RBCmd and $I_Parse 

:- Click Me

Mastering LECmd.exe

image.png

"During a forensic examination of a hard drive, LNK files can determine what programs and files a user were accessing on their computer."

LECmd: A Powerful Tool for Investigating LNK Files      :- Click Me

Plaso/Log2Timeline 

image.png

"Plaso is the Python-based backend engine powering log2timeline, while log2timeline is the tool we use to extract timestamps and forensic artifacts. Together, they create what we call a super timeline—a comprehensive chronological record of system activity."

A Deep Dive into Plaso/Log2Timeline Forensic (Ubuntu)    :- Click Me

Running Plaso/Log2Timeline on (Windows)                        :- Click Me

File recovery : PhotoRec

image.png

"Photorec is a versatile data recovery program that reads file headers and targets various media file types"

Data Recovery and Analysis     :- Click Me

SRUM Analysis, Tools (NUV), ESEDATABASE View, SrumECmd.exe

SRUM_ The Digital Detective in Windows.jpg

"System Resource Usage Monitor (SRUM), a powerful tool that has become a game-changer in digital forensic investigations.

ESEDatabaseView                    :- Click Me

NirSoft Network Usage View     :- Click Me

SrumECmd                               :- Click Me

SRUM-DUMP v3                       :- Click Me

Kernal PST and OST File Viewers

image.png

"These tools not only simplify the extraction and viewing of data but also ensure compatibility across different file formats and versions."

Exploring PST and OST File Viewers for Forensic Analysis    :- Click Me

MetaDiver:  Forensic Analysis Tool

metadata.jpg

"MetaDiver is a powerful forensic tool designed to analyze and extract metadata from various file types.."

MetaDiver: A Comprehensive Forensic Analysis Tool( for metadata analysis)   :- Click Me

DB Browser for Forensic Analysis

Google, firefox, Interne explorer, edge combines.jpg

"Freely available, it has become a favorite not only for database administrators but also for forensic analysts..."

 Power of DB Browser for Forensic Analysis   :- Click Me

WinAudit Tool Overview

Computer.jpg

"Freely available, it has become a favorite not only for database administrators but also for forensic analystsWinAudit.exe is one such tool that delivers a detailed audit of your system, offering essential data to strengthen your cybersecurity posture."

WinAudit Tool Overview   :- Click Me

Netcat Tool Overview

netcat.jpg

"This tool allows seamless data transfer across networks, similar to the UNIX cat command, but instead of reading and writing to files, Netcat communicates over TCP and UDP ports.."

Netcat: A Hacker's Swiss Army Knife   :- Click Me

Defensive Measures Against Netcat   :- Click Me

Windows Security with Log-MD

Ransomware.jpg

"Log-MD is a security tool tailored for Windows systems. It audits log settings and advanced audit policy configurations, guiding users to enable and configure these settings for better security and detection.."

Enhancing Windows Security with Log-MD   :- Click Me

Bitmap Cache Files

Remote desktop cache.jpg

"When dealing with Remote Desktop Protocol (RDP) sessions on Windows, one of the often overlooked yet valuable artifacts is the RDP bitmap cache..."

Analyzing and Extracting Bitmap Cache Files from RDP Sessions  :- Click Me

Aurora Incident Response

Aurora Incident Response.jpg

"While experienced teams can still thrive using traditional tools like Excel, Aurora Incident Response (Aurora IR) stands out as a fantastic free and open-source solution for those who need a more structured and user-friendly approach to investigations."

Aurora Incident Response: A Powerful Open-Source Tool for Investigators  :- Click Me

RECmd

Registry.jpg

"RECmd, a powerful command-line tool created by Eric Zimmerman, designed to automate the process of registry analysis."

Automating Registry Analysis with RECmd :- Click Me

Attack Surface Analyzer (ASA)

Analyzing System Security with Attack Surface Analyzer (ASA).jpg

"Microsoft tool that helps you capture and compare snapshots of your system’s state so you can see what changed before and after an installation."

Analyzing System Security with Attack Surface Analyzer :- Click Me

bottom of page