#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.
A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Python implementation of the CaRT library for (un)inerting files.

bad stuffs by bad guys

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Walk x86-64 page tables by hand in qemu and gdb. Decompose a virtual address, follow cr3 through all levels of physical memory, and extract a flag…

Generate bulk YARA rules from YAML input

Copy Fail - CVE-2026-31431

Original PoC for CVE-2023-30367

Research project related to memory address analysis

Bro analyzer that detects Google's QUIC protocol

Post-Exploitation EVTX Analyzer for BloodHound Mapping

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Exploit for CVE-2023-5178

Parsing Ramnit's traffic

Passive hybrid fingerprinting engine — identify hosts without sending a single packet