#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

CVE-2025-31200 - @Noahhw46 figured it out

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

GPG Reaper - Obtain/Steal/Restore GPG Private Keys from gpg-agent cache/memory

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

Learning Linux Binary Analysis, published by Packt

Monitoring Registry and File Changes in Windows

Java Agent memory horse scanner combined with Call Graph modus

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.

Use-After-Free in Netfilter nf_tables when processing batch requests CVE-2023-32233

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

Extract registry and NTDS secrets from local or remote disk images

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Proof-of-concept for CVE-2025-27363 demonstrating a heap buffer overflow in FreeType 2.13.0 via a crafted variable font, with ASAN-verified crash…

Kernel Stack info leak at exportObjectToClient function

POC for CVE-2015-6620, AMessage unmarshal arbitrary write