Binalyze AIR is a modern digital forensics and incident response platform that offers a comprehensive set of tools for reducing incident response time, including a DFIR guide, compromise assessment solution, and an all-in-one evidence collector.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix's Security Intelligence and Response Team (SIRT) for scoping compromises across cloud instances.
A network forensics toolkit that transforms network traffic data into graph-based representations for interactive analysis and visualization through a web interface.
A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.
Powerful tool for searching and hunting through Windows forensic artefacts with support for Sigma detection rules and custom Chainsaw detection rules.
Malscan is a tool to scan process memory for YARA matches and execute Python scripts.
Fridump is an open source memory dumping tool using the Frida framework for dumping memory addresses from various platforms.
A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.
MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.