
uac
Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Simple Process Dumper using DMA over a PCIe FPGA device

Linux Process Discovery. C Library, Go bindings, Runtime.

Enumerate various traits from Windows processes as an aid to threat hunting

Scan files or process memory for CobaltStrike beacons and parse their configuration

Visualize the virtual address space of a Windows process on a Hilbert curve.

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

VirtualBox Disk Image Encryption password cracker