#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Open source Android Forensics app and framework

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Indicator of Compromise Scanner for CVE-2019-19781

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819

Demonstrates type confusion and heap overflow exploits for CVE-2015-4843 in Java, with demos for aarch64 and Morello, highlighting CHERI capability…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

PoC for CVE-2021-32537: an out-of-bounds memory access that leads to pool corruption in the Windows kernel.

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

CVE-2020-1206 Uninitialized Kernel Memory Read POC

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Graph platform for Detection and Response

A forensic evidence collection & analysis toolkit for OS X