#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Records calls from a Trunked Radio System (P25 & SmartNet)

Automation and Scaling of Digital Forensics Tools

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

Automates Linux swap analysis to extract user credentials, web form data, WiFi keys, and HTTP authentication during post-exploitation or forensic…

Windows passwords decryption from dump files

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Code Injection, Inject malicious payload via pagetables pml4.

Extract AutoIt scripts embedded in PE binaries

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Memoro: A Detailed Heap Profiler

Tools for the Computer Incident Response Team :computer: