
usbsnoop
Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Tool to extract the $UsnJrnl from an NTFS volume

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Dump TeamViewer ID and password from memory. Works much better than other tools.

Extract indicators of compromise from text, including "escaped" ones.

Small toolkit for extracting information and dumping sensitive strings from Windows processes

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Generates YARA rules from installed software on a running OS to baseline known software and find similar installations across digital forensic…

IoCs and YARA rules from Threatray's Threat Research

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

A python tool that will extract exif data from picture with two methods

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…