
Loki
IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This is the development tree. Production downloads are at:


CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.
