#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…
It was developed to speed up the processes of SOC Analysts during analysis

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

CVE-2026-23111

Technical analysis of CVE-2020-1206 (SMBleed) kernel information disclosure vulnerability in Windows SMBv3, including unauthenticated memory leak…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

OpenStego is a steganography application that provides two functionalities: a) Data Hiding: It can hide any data within an image file. b)…

CVE-2025-14847 (MongoBleed)

Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

Technical notes and debugger analysis for CVE-2014-4140, a use-after-free vulnerability in MSHTML's CHtmRootParseCtx::AddText leading to remote code…

This repo contains instructions to reproduce CVE-2025-13425: Null Pointer dereference / Array over-indexing vulnerability that I found in Google's…

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Hunt down social media accounts by username across social networks

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Repository to index useful tools for CTF's

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…