#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…
Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

NetworkAssessment: Network Compromise Assessment Tool

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Useful resources for SOC Analyst and SOC Analyst candidates.

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Collection of forensic tools

Radare2 and Frida better together.

A memory-based evasion technique which makes shellcode invisible from process start to end.

A centralized and enhanced memory analysis platform

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…