#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

A tool for finding and analyzing private (and public) key files, including support for Android APK files.

EDRSandblast-GodFault

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Differential Analysis of Malware in Memory

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

CVE-2020-1206 Uninitialized Kernel Memory Read POC

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Finding secrets in kernel and user memory

Kirjuri is a web application for managing cases and physical forensic evidence items.

Indicator of Compromise Scanner for CVE-2019-19781


Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

PoC for CVE-2021-32537: an out-of-bounds memory access that leads to pool corruption in the Windows kernel.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.