
FACT
Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Visualize the virtual address space of a Windows process on a Hilbert curve.

Scan files or process memory for CobaltStrike beacons and parse their configuration

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.