
Process-Dump
Windows tool for dumping malware PE files from memory back to disk for analysis.

Windows tool for dumping malware PE files from memory back to disk for analysis.

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW…

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

WITCHCRAFT is a cyberdeck toolkit built for runners who dive deep into the mesh. It’s your all-in-one rig for data-ghosting, ICE-breaking, and…

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Crack iOS Restriction Passcodes with Python

A Repository to Track Anti-Forensic Techniques

Deep File Forensic. Create or manipulate Wordlists out of Text Documents (ex: for BruteForcing). Save it Line by Line as a Binary .BIN File or as a…

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Crack ios Restriction PassCode in Python