#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs


Awesome list of keywords and artifacts for Threat Hunting sessions

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Android 14 kernel exploit for Pixel7/8 Pro

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

tool to extract passwords from TeamViewer memory using Frida

Forensics artefact collection tool for systems running Microsoft Windows

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

ROP-based sleep obfuscation to evade memory scanners

Digital forensic acquisition tool for Windows based incident response.

helps visualize heap operations for pwn and debugging

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

A python script developed to process Windows memory images based on triage type.

Incident Response - Fast suspicious file finder

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"