
pdfresurrect
Analyze and help extract older "hidden" versions of a pdf from the current pdf.

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

A python tool that will extract exif data from picture with two methods

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Lua plugin to extract data from Wireshark and convert it into MISP format

A tool to use novel locations to extract metadata from Office documents.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Volatility plugin to extract X screenshots from a memory dump

Extract registry and NTDS secrets from local or remote disk images

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Generate bulk YARA rules from YAML input

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…