
LSB-Steganography
Python program to steganography files into images using the Least Significant Bit.

Python program to steganography files into images using the Least Significant Bit.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Script to remove homoglyphs and zero-width characters to allow for safe distribution of documents from anonymous sources.

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

A low pin count sniffer for ICEStick - targeting TPM chips

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates…

Python script that will extract all saved passwords from your google chrome database on windows only

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…