
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Forensics artefact collection tool for systems running Microsoft Windows

A GUI and CLI tool for removing bloat from executables

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

A small utility to translate NTDS.dit files to SQLite format.

An OSINT / digital forensics tool built in Python

Digital Forensics Intelligence Framework

A tool to use novel locations to extract metadata from Office documents.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Utility for recovering ES File Explorer encrypted files (.eslock)

This is the development tree. Production downloads are at:

A python tool that will extract exif data from picture with two methods

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303
