Skip to content
dfirws tools
pycares
Search
dfirws tools
Welcome to the dfirws wiki
Changelog
Customize dfirws
Didier Stevens tools
Getting started
Jupyter notebooks
KAPE
Network forensics
Notebook for PE with Ghidra and capa
Obsidian
Samples
Windows forensics
Investigations
Investigations
Investigate Email
Investigate JavaScript files
Investigate MSI files
Investigate Office files
Investigate OneNote files
Investigate PDF files
Investigate PE files
Investigate PowerShell
Investigate ZIP files
Tools
Tools
Categories
Cloud
Cloud
Cloud
Azure CLI
Development
Development
Development
MEX
Microsoft OpenJDK 11
Win API Search
Editors
Editors
Editors
admonitions
bytecode-viewer
ComparePlus
DSpellCheck
HxD
ImHex
Malcat Lite
Neovim
Notepad++
obsidian-calendar-plugin
obsidian-dataview
obsidian-excalidraw-plugin
obsidian-kanban
obsidian-mitre-attack
obsidian-tasks
obsidian-timeline
Obsidian
quickadd
Templater
Visual Studio Code
VS Code PowerShell Extension
VS Code Spell Checker
vscode-shellcheck
Enrichment geolocation
Enrichment geolocation
Enrichment / Geolocation
Geolocus
IPinfo Country ASN
MaxMind GeoLite2 ASN
MaxMind GeoLite2 City
MaxMind GeoLite2 Country
Enrichment ids
Enrichment ids
Enrichment / IDS
Snort Rules
Suricata Rules
Enrichment network
Enrichment network
Enrichment / Network
TOR Exit Nodes
Wireshark Manuf
X4BNet Bots List
X4BNet Cloudflare List
X4BNet Route53 List
X4BNet Search Engine List
X4BNet StopForumSpam
X4BNet TOR Exit List
X4BNet UptimeRobot List
X4BNet VPN List
Enrichment threat intelligence
Enrichment threat intelligence
Enrichment / Threat Intelligence
SSC-Threat-Intel-IoCs
Volexity Threat Intel
Enrichment vulnerability
Enrichment vulnerability
Enrichment / Vulnerability
CVE Data
Enrichment yara
Enrichment yara
Enrichment / YARA
YARA Forge Rules Core
YARA Forge Rules Extended
YARA Forge Rules Full
Files and apps
Files and apps
Files and apps
autoit-ripper
binlex
bulk_extractor
cabarchive
DensityScout
Detect It Easy
Dumpbin
fq
jq
lessmsi
magika
msidump
oletools
Python-dsstore
python-magic
pyzipper
QEMU
qrtool
ripgrep
TrID
unpy2exe
WinMerge
Files and apps browser
Files and apps browser
Files and apps / Browser
dfir-unfurl
HindSight
NirSoft Browser Utilities
Files and apps database
Files and apps database
Files and apps / Database
DB Browser for SQLite
DBeaver
dsq
elasticsearch
ese-analyst
fqlite
h2database
litecli
neo4j
Neo4j
sqlit-tui
SQLite Tools
Files and apps disk
Files and apps disk
Files and apps / Disk
dfir_ntfs
INDXRipper
MFTBrowser
OSFMount
Sleuthkit
Files and apps email
Files and apps email
Files and apps / Email
Aspose.Email-for-Python-via-Net
EmailAnalyzer
extract-msg
Mail Viewer
mboxviewer
MsgViewer
PST Walker
Files and apps javascript
Files and apps javascript
Files and apps / JavaScript
box-js
deobfuscator
jsbeautifier
jsdom
Files and apps log
Files and apps log
Files and apps / Log
APT-Hunter
chainsaw
dfir-toolkit
Elastic Stack (ELK + Beats)
EVTX-ATTACK-SAMPLES
evtx_dump
evtx
flatten_json
fx
gron
hayabusa-rules
hayabusa
LogBoost
LUMEN
MasterParser
takajo
ToolAnalysisResultSheet
toolong
YAMAGoya
Zircolite
Files and apps mobile
Files and apps mobile
Files and apps / Mobile
aLEAPP
iLEAPP
iShutdown
libimobiledevice-windows
Files and apps office
Files and apps office
Files and apps / Office
compressed_rtf
docx2txt
LibreOffice
MetadataPlus
MiTeC Structured Storage Viewer
msoffcrypto-tool
OfficeMalScanner
olefile
openpyxl
pcode2code
pyOneNote
python-docx
XLMMacroDeobfuscator
xlrd
XlsxWriter
Files and apps pdf
Files and apps pdf
Files and apps / PDF
Foxit PDF Reader
pdfalyzer
PDFStreamDumper
peepdf-3
pypdf
qpdf
Files and apps pe
Files and apps pe
Files and apps / PE
4n4lDetector
ASL
capa Explorer Web
capa-rules
capa
debloat
dll_to_exe
hachoir
HollowsHunter
lief
PE-bear
PE-sieve
PE-utils
pefile
pestudio
peutils
pfp
readpe
WinObjEx64
Files and apps rdp
Files and apps rdp
Files and apps / RDP
bmc-tools
RdpCacheStitcher
Forensics
Forensics
Forensics
acquire
artemis
autopsy_addon_modules
Autopsy
binary-refinery
cart
DFIRArtifactMuseum
dfirws-sample-files
dissect.target
dissect
flow.record
msticpy
one-extract
pathlab
PyrsistenceSniper
RDPCacheStitcher
White-Phoenix
Incident response
Incident response
Incident Response
forensic-timeliner
Incident-Response-Powershell
Witr
Ir
Ir
IR
PowerSponse
Trawler
Velociraptor
white-phoenix
Logs
Logs
Logs
FullEventLogView
Malware analysis
Malware analysis
Malware Analysis
mwcp
speakeasy
Malware analysis cobalt strike
Malware analysis cobalt strike
Malware Analysis / Cobalt Strike
BeaconHunter
CobaltStrikeScan
Malware tools
Malware tools
Malware tools
ClamAV
csvkit
defender-detectionhistory-parser
maldump
Malware tools gootloader
Malware tools gootloader
Malware tools / Gootloader
gootloader
Memory
Memory
Memory
Dokany
LeechCore.wiki
MemProcFS.wiki
MemProcFS
minidump
Volatility Workbench 2.1
Volatility Workbench 3
winpmem
Network
Network
Network
Burp Suite
dnslib
dpkt
Flare-Fakenet-NG
geoip2
hfs
maclookup
Microsoft.etl2pcapng
netaddr
NetworkMiner
Nmap
Npcap
OpenVPN
PacketCircle
paramiko
protodeep
PuTTY
pycares
pydivert
pyshark
PySocks
scapy
Tailscale
WireGuard
Wireshark
zaproxy
Zui
Os android
Os android
OS / Android
Android SDK Platform Tools
apktool
Os linux
Os linux
OS / Linux
Elfparser-ng
XELFViewer
Os windows
Os windows
OS / Windows
API Monitor
BlueTuxedo
CimSweep
Fibratus
Jumplist Browser
LnkParse3
Prefetch Browser
ProcDOT
psexposed
recbin
sidr
srum_dump
Thumbcacheviewer
TotalRecall
usnjrnl
Os windows active directory
Os windows active directory
OS / Windows / Active Directory
adalanche
DitExplorer
Os windows registry
Os windows registry
OS / Windows / Registry
python-registry
regipy-mcp-server
regipy
RegShot
Programming
Programming
Programming
JavaFX SDK
NodeJS
PHP
Python 3.11
Strawberry Perl
Programming dotnet
Programming dotnet
Programming / dotNET
DotNet 6 Desktop Runtime
DotNet 8 Desktop Runtime
DotNet 9 Desktop Runtime
dotnetfile
dotnetfile
Programming go
Programming go
Programming / Go
gftrace
GoLang
GoReSym
GoReSym
gostringungarbler
redress
Programming java
Programming java
Programming / Java
Amazon Corretto 21
jadx
javaobj-py3
jd-gui
jwt-cli
Recaf
Programming powershell
Programming powershell
Programming / PowerShell
deobshell
PowerDecode
PowerShell 7
PowerShell
Programming python
Programming python
Programming / Python
aiodns
aiohttp
BeautifulSoup4
bitstruct
matplotlib
networkx
numpy
orjson
ptpython
pyasn1
python-dotenv
requests
simplejson
termcolor
textsearch
tomlkit
treelib
uv
xxhash
Programming ruby
Programming ruby
Programming / Ruby
Ruby
Programming rust
Programming rust
Programming / Rust
Rust
Reverse engineering
Reverse engineering
Reverse Engineering
Binary Ninja
CapaExplorer
cutter-jupyter
Cutter
cutterref
decai
dnSpy
FASM
frida-tools
Ghidra BTIGhidra
Ghidra Cartographer
Ghidra GhidrAssistMCP
Ghidra GolangAnalyzerExtension
Ghidra
ghidrecomp
ghidriff
Iaito
IDR
ILSpy
keystone-engine
NetExt
pyghidra
r2ai
r2ai
radare2-deep-graph
radare2-mcp
Radare2
rzpipe
scare
unicorn
WinDbg
x64dbg
Signatures and information
Signatures and information
Signatures and information
chainsaw-rules
god-mode-rules
legacy-sigmatools
Loki
mkyara
MSRC
PatchaPalooza
ppdeep
pysigma-backend-elasticsearch
pySigma-backend-loki
pysigma-backend-splunk
pysigma-backend-sqlite
pysigma-pipeline-sysmon
pysigma-pipeline-windows
Shadow-Pulse
sigma-cli
sigma
signature-base
threat-intel
yara-python
yara-x
YARA
yq
Signatures and information online tools
Signatures and information online tools
Signatures and information / Online tools
gti-dev-kit
malware-bazaar-advanced-search
malwarebazaar
shodan
VirusTotal CLI
Sysinternals
Sysinternals
Sysinternals
Sysinternals Suite
Uncategorized
Uncategorized
Uncategorized
CuTE-tui
SSHniff
Utilities
Utilities
Utilities
7-Zip
ai-fs-proxy
cmder
DCode
deep_translator
Dependencies
dictionaries
docsify-cli
edit
ExifTool
Flare-Floss
geolocus-cli
git
go-size-analyzer
godap
Google Earth Pro
graphviz
Graphviz
grip
hexdump
jpterm
jupyter-collection
jupyterlab
markitdown
@marp-team/marp-cli
mcp-server-elasticsearch
mkdocs
mmdbinspect
Nerd Fonts
oh-my-posh
opencode-ai
prettytable
pwncat
pyvis
Resource Hacker
rexi
RpcView
time-decode
ULogViewer
upx
Velociraptor Artifact Exchange
visidata
Windows Terminal (Canary)
zensical
zstd
Utilities browsers
Utilities browsers
Utilities / Browsers
Chrome
Firefox
Tor Browser
Utilities cryptography
Utilities cryptography
Utilities / Cryptography
Ares
chepy
CyberChef
Gpg4win
hashcat
name-that-hash
pycryptodome
VeraCrypt
Utilities ctf
Utilities ctf
Utilities / CTF
HiddenWave
pypng
stego-lsb
Utilities media
Utilities media
Utilities / Media
Audacity
ffmpeg
IrfanView
SmartDeblur
VLC
pycares
¶
Category:
Network
Source:
Python
Profiles:
Full, Basic
Tags:
network, dns