
DMA-ProcessDumper
Simple Process Dumper using DMA over a PCIe FPGA device

Simple Process Dumper using DMA over a PCIe FPGA device

Visualize the virtual address space of a Windows process on a Hilbert curve.

Enumerate various traits from Windows processes as an aid to threat hunting

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

VirtualBox Disk Image Encryption password cracker

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Linux Process Discovery. C Library, Go bindings, Runtime.

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…