
binwally
Binary and Directory tree comparison tool using Fuzzy Hashing

Binary and Directory tree comparison tool using Fuzzy Hashing


Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Windows link file (shortcuts) examiner

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Online Reverse Enginerring viewer

A multi-platform GUI for bit-based analysis, processing, and visualization

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…