
lmg
Script for automating Linux memory capture and analysis

Script for automating Linux memory capture and analysis

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Cross-platform CUI process memory scanner built on Frida for finding, filtering, patching, and dumping live process memory during reverse engineering…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Interactive documentation and visual reference for binary formats and system memory layouts.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Process heap analysis framework - Windows/Linux - record type inference and forensics

Scientific investigation of hardware vulnerabilities (CVE-2025-6202, CVE-2023-39910) enabling ECDSA key recovery from Bitcoin infrastructure via…

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Analysis and remediation guide for CVE-2025-14847 (MongoBleed), a MongoDB zlib compression memory disclosure. Includes detection indicators,…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

An advanced memory forensics framework

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.