
oletools
Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Python implementation of the CaRT library for (un)inerting files.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

KeePass 2.X dumper (CVE-2023-32784)

An advanced memory forensics framework

Mimikatz implementation in pure Python

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

Extract AutoIt scripts embedded in PE binaries

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Volatility 3 ported to Rust. Same output, much faster.

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Python toolkit for malware analysis, designed to inspect suspicious files and extract indicators of compromise for security investigations.

Python script for carving Bitlocker VMK keys

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

WhatsApp Forensic Tool