
memory-forensic
Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

bad stuffs by bad guys

Parser for $LogFile on NTFS

Binary template repository for 010 Editor, providing .bt scripts for parsing executables, filesystem images, registry hives, and forensic artifacts…

Library to access the Windows Shell Item format

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

Utility for recovering ES File Explorer encrypted files (.eslock)

Binary and Directory tree comparison tool using Fuzzy Hashing


android location service cache dumper


Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.