
acropalypse-reconstructor
A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Mediatek Flash and Repair Utility

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Static-first research tool for unpacking Nuitka-compiled binaries: extracts constants, modules, recovers .pyc files, and generates analysis reports.

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

A multi-platform GUI for bit-based analysis, processing, and visualization

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

This is the development tree. Production downloads are at:

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Hive v5 file decryption algorithm