
pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

A network packet forensics tool for SSH

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

OSINT tool researched and designed to hunt down IG handles

Live kernel signal observability tool using eBPF tracepoints to stream every signal raised on a Linux host, showing sender, target, disposition,…

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Blockchain Transactions Investigation Tool

Artifact collection tool for *nix systems

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

E2E encryption for multi-hop tty sessions or portshells + TCP/UDP port forward

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Detection Script for MongoBleed Exploitation

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs