
whatfiles
Log what files are accessed by any Linux process

Log what files are accessed by any Linux process

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Utility to find AES keys in running processes

Linux Memory Cryptographic Keys Extractor

VirtualBox Disk Image Encryption password cracker

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

Process heap analysis framework - Windows/Linux - record type inference and forensics

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Detect Linux rootkits which use signals to elevate process privileges.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

the ps utility, with an eBPF twist and container context

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…