
teamviewer-dumper
Dump TeamViewer ID and password from memory. Works much better than other tools.

Dump TeamViewer ID and password from memory. Works much better than other tools.

Extract indicators of compromise from text, including "escaped" ones.

Pcap (capture file) Analysis Toolkit(v.1)

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

Python script that will extract all saved passwords from your google chrome database on windows only

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Modular malware analysis artifact collection and correlation framework

Download and View Skype History Without Skype

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

Windows link file (shortcuts) examiner


A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

A python tool that will extract exif data from picture with two methods

Volatility plugin to extract X screenshots from a memory dump


Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally