
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

UNIX-like reverse engineering framework and command-line toolset.


Process heap analysis framework - Windows/Linux - record type inference and forensics

Malicious HTTP traffic explorer

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Labtainers: A Docker-based cyber lab framework

An advanced memory forensics framework