
FACT
Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Visualize the virtual address space of a Windows process on a Hilbert curve.

Enumerate various traits from Windows processes as an aid to threat hunting

Scan files or process memory for CobaltStrike beacons and parse their configuration

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Simple Process Dumper using DMA over a PCIe FPGA device

VirtualBox Disk Image Encryption password cracker

Linux Process Discovery. C Library, Go bindings, Runtime.

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…