
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…


Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A small utility to translate NTDS.dit files to SQLite format.

DPAPI looting remotely and locally in Python

Some usefull Scripts and Executables for Pentest & Forensics

Decrypt GlobalProtect configuration and cookie files.

Lnk crafting and research tools

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Extract registry and NTDS secrets from local or remote disk images

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Digital Forensics Intelligence Framework

A simple Toolkit to BF and decrypt Windows EntraId CacheData

[Linux] Two Privilege Escalation techniques abusing sudo token

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR