
pcileech
Direct Memory Access (DMA) Attack Software

Direct Memory Access (DMA) Attack Software

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

A cross-platform java application for decoding, monitoring, recording and streaming trunked mobile and related radio protocols using Software Defined…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Records calls from a Trunked Radio System (P25 & SmartNet)

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Labtainers: A Docker-based cyber lab framework

Linux Memory Cryptographic Keys Extractor

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Rip Raw is a small tool to analyse the memory of compromised Linux systems.


Finding secrets in kernel and user memory

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.