{"repo":"Johnng007/Live-Forensicator","free":true,"listed":false,"github":"https://github.com/Johnng007/Live-Forensicator","clone":"git clone https://github.com/Johnng007/Live-Forensicator.git","description":"Cross-platform incident response and live forensics toolkit with built-in detection, structured analysis, and report generation — designed for fast, actionable security investigations.","language":"PowerShell","stars":630,"topics":["incident-response","forensics","forensics-investigations","live-forensic","log4j","powershell","forensicator","ransomeware","eventlogs","eventlog-analysis"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"🛡️ Forensicator 🛡️ Cross-platform Incident Response & Live Forensics Toolkit Windows (PowerShell) Linux (Bash) macOS (Shell) Built for fast, structured, and actionable forensic investigations. --- 🤔 About Forensicator is a cross-platform incident response and live forensics toolkit. It is designed to help forensic investigators and incident responders rapidly collect, analyze, and interpret system artifacts during live investigations. Forensicator: Collects system and user activity data Detects anomalous behavior and suspicious indicators Highlights potential compromise or misconfiguration Generates structured, investigation-ready HTML reports --- ⚙️ Platform Support 🖳 Windows (PowerShell) Advanced Event Log analysis Detection of suspicious activity via known Event IDs Sigma rule engine (1,400+ community rules) evaluated against Security/Sysmon Event Logs Malware hash matching (e.g., abuse.ch feeds) Browser history analysis with IOC matching Optional artifact encryption (AES) Detection Insight - a summary of the detection, why it matters, the detection logic, what to look for, and its MITRE mapping Investigation archive + structured JSON output for Forensicator Enterprise Forensicator AI — optional, per-finding AI verdicts from a local (Ollama) or commercial LLM, shown in the report's tooltip 👉 https://github.com/Johnng007/Live-Forensicator/tree/main/Windows --- 🍎 macOS (Shell) Detection engine covering reverse shells, SIP/Gatekeeper/kext tampering, PATH hijacking, dele","default_branch":null,"files":null,"tree":[],"storefront":"/r/Johnng007","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Johnng007/Live-Forensicator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}