
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

A python script developed to process Windows memory images based on triage type.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Android Connections Forensics

A canary designed to minimize the impact from certain Ransomware actors

[Linux] Two Privilege Escalation techniques abusing sudo token

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Process heap analysis framework - Windows/Linux - record type inference and forensics