
AMBER-ICI
AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph…

AMBER ICI v5: local-first Ollama investigative command center with case-scoped evidence, agent chains, hybrid retrieval, streaming analysis, graph…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Automated steganography detection tool that scans websites, web servers, and local directories using AI-driven object/text recognition and deep file…

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A portable C# utility for enumerating local and remote windows sessions

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…

Local steganography app for hiding text, images, or files inside carrier images with AES-256 encryption, EXIF editing, watermarking, and batch…

A report on Dirty Frag, which is a Linux Local Privilege Escalation (LPE) vulnerability chain that allows an unprivileged user to gain root access

Forensic Analysis and Local Replication of the OpenAI-Artifactory Privilege Escalation Incident (CVE-2026-65616)

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Builds malware analysis Windows VMs so that you don't have to.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…


Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.