
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Investigation of CVE-2024-4577 exploitation and AsyncRAT deployment with DFIR artifacts, IoCs, and detection guidance.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…


This repository serves as a place for community created Targets and Modules for use with KAPE.

This repository contains a list of new remediation scripts.

Forensics artefact collection tool for systems running Microsoft Windows

bad stuffs by bad guys

Evtx Log (xml) Browser

Current links from the OSINT Inception start-me project

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely