
poc_CVE-2021-36934
POC experiments with Volume Shadow copy Service (VSS)

POC experiments with Volume Shadow copy Service (VSS)

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Parser for $LogFile on NTFS

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

Search and extract blob files on the Ethereum Blockchain network

Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.

Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Wipe, reinstall or restore your system from running GNU/Linux distribution. Via SSH, without rebooting.