


A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Experimental Windows .text section Patch Detector

RAM imaging utility.

A simple, reliable and reasonably fast network capture analyzer.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Rapidly Search and Hunt through Windows Forensic Artefacts

Dshell is a network forensic analysis framework.

A free, open-source, and cross-platform iDevice management tool

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Cortex: a Powerful Observable Analysis and Active Response Engine

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Extract Windows credentials directly from VM memory snapshots and virtual disks

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.