
NtWarden
Windows Analysis and Research Toolkit

Windows Analysis and Research Toolkit

Script for automating Linux memory capture and analysis

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Process heap analysis framework - Windows/Linux - record type inference and forensics

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.