
HiddenNetworks-Python
USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

GUI for Volatility forensics tool written in PyQT5

Tool for checking passwords against TrueCrypt encrypted volumes and disks, and/or decrypting the data.

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

A utility for extracting cryptocurrency wallet data from wallet.dat files.

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

A tool for finding and analyzing private (and public) key files, including support for Android APK files.

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

E-Mail Header Analyzer


Detection and sanitization for Acropalypse Now - CVE-2023-21036

Detection Script for MongoBleed Exploitation