
GhostTrace
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Direct Memory Access (DMA) Attack Software

Original PoC for CVE-2023-32784

Digital forensic acquisition tool for Windows based incident response.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Windows link file (shortcuts) examiner

KeePass 2.X dumper (CVE-2023-32784)

The multi-platform memory acquisition tool.

Automagically extract forensic timeline from volatile memory dump

A Windows kernel dump C++ parser library with Python 3 bindings.

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

GUI for Volatility forensics tool written in PyQT5