
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Forensics artefact collection tool for systems running Microsoft Windows

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

An OSINT / digital forensics tool built in Python

A tool to use novel locations to extract metadata from Office documents.

This is the development tree. Production downloads are at:

A python tool that will extract exif data from picture with two methods

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more


This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

E-Mail Header Analyzer

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.