#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

Configuration Extractors for Malware

Cross-platform registry browser for raw Windows registry files

This is POC for IOS 0click CVE-2025-43300

Small toolkit for extracting information and dumping sensitive strings from Windows processes

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

macOS forensic timeline generator using the analysis result DBs of mac_apt

POC for CVE-2018-0824

Tool for CVE-2018-16323

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

Java Agent memory horse scanner combined with Call Graph modus

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

Download and View Skype History Without Skype

Spectre exploit

CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)