MANDIANT IOC Finder is a free tool for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). More
MANDIANT IOC Editor is a free editor for Indicators of Compromise (IOCs). More
MANDIANT Redline is a free utility that accelerates the process of triaging hosts suspected of being compromised or infected while supporting in-depth live memory analysis
Current Version: Redline 1.1.1
Release Date: February 3, 2012
Free memory forensics software designed to help incident responders find evil within live memory.
Current Version: Memoryze 2.0 Release Date: October 17, 2011More
Highlighter is designed to help security analysts and system administrators rapidly review log and other structured text files. More
Audit Viewer is an open source tool that allows users to examine the results of Memoryze's analysis. More
Software for incident responders that helps find and analyze unknown malware. More
Assists users in reviewing websites that are stored in the history files of the most commonly used browsers. More
MIR Lite-CDT is a command line utility based on technology from MANDIANT's Intelligent Response enterprise product. More
ApateDNS is a tool for controlling DNS responses though an easy to use GUI. As a phony DNS server, ApateDNS spoofs DNS responses to a user-specified IP address by listening on UDP port 53 on the local machine. ApateDNS also automatically sets the local DNS to localhost. Upon exiting the tool, it sets back the original local DNS settings. More
The Metasploit Forensic Framework (MSFF) is a proof of concept tool that can potentially reconstruct an attacker's meterpreter sessions, allowing analysts to see some of the commands sent and received by the attacker from the metasploit console to the meterpreter server. It can give analysts a much better picture of what occurred. More
MindSniffer is a tool that will allow the user to translate snort signatures to either XML jobs or Python plug-ins that can be used to identify processes containing strings that match snort signatures. More
A simple forensic tool to analyze change.log files from restore points to determine the original paths and file names of files stored inside restore points. More