
gv_decryptor
Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Filesystem monitor tool for Linux/Android iOS/macOS

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Decodes PlugX traffic and encrypted/compressed artifacts

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065

This is the development tree. Production downloads are at:

Detection Script for MongoBleed Exploitation

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Detection of malicious VHD files for CVE-2025-24985

Mimikatz implementation in pure Python