
SessionView
A portable C# utility for enumerating local and remote windows sessions

A portable C# utility for enumerating local and remote windows sessions

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…


Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph…

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Extract registry and NTDS secrets from local or remote disk images

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.