#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

memory search and patch tool on debuggable apk without root & ndk
Live hunting of code injection techniques

PowerShell module for Office 365 and Azure log collection

.NET runtime inspector

An automatic unpacker and logger for DotNet Framework targeting files

Main repository to pull all NCC Group Cisco ASA-related tool projects.

Using CVE-2023-21768 to manual map kernel mode driver

Blue Team detection lab created with Terraform and Ansible in Azure.

A ProcessMonitor visualization application written in rust.

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Script to remove homoglyphs and zero-width characters to allow for safe distribution of documents from anonymous sources.

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Linux kernel use-after-free (UAF) privilege escalation exploit for CVE-2018-17182, providing root shell access on affected kernels (3.16 to 4.18.8).…

Tool to make in memory man in the middle

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

PoC and technical details of CVE-2025-24204