
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A python script developed to process Windows memory images based on triage type.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

A canary designed to minimize the impact from certain Ransomware actors

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Visualize the virtual address space of a Windows process on a Hilbert curve.

Log what files are accessed by any Linux process

Linux Memory Cryptographic Keys Extractor

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

Process heap analysis framework - Windows/Linux - record type inference and forensics