
clairvoyance
Visualize the virtual address space of a Windows process on a Hilbert curve.

Visualize the virtual address space of a Windows process on a Hilbert curve.

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction

[Linux] Two Privilege Escalation techniques abusing sudo token

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Windows passwords decryption from dump files

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

volatility explorer (volatility 2)


SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Telegram intelligence collection tool for researchers and investigators. Scrapes groups, messages, media, and user data with OCR, Elasticsearch…


Finding secrets in kernel and user memory
