
vol-rs
Volatility 3 ported to Rust. Same output, much faster.

Volatility 3 ported to Rust. Same output, much faster.

Total Commander FTP Password Recovery Tool for Python allows you to decrypt the FTP account password information for all Total Commander versions…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

ESF modular ingestion tool for development and research.

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation

YARA rule and python script to detect potential exploits for the CVE-2026-21509 vulnerability in MS Office

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.


Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

All-in-one Image Steganography Toolkit for CTFs & Forensics

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the Virtual Hard Disk (VHD) image format

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…