
DetectWindowsCopyOnWriteForAPI
Enumerate various traits from Windows processes as an aid to threat hunting

Enumerate various traits from Windows processes as an aid to threat hunting

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Lightweight macOS malware analysis sandbox that monitors system activity via OpenBSM or Monitor.app, generating detailed reports and timelines of…

Simple Process Dumper using DMA over a PCIe FPGA device

Visualize the virtual address space of a Windows process on a Hilbert curve.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

VirtualBox Disk Image Encryption password cracker

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Linux Process Discovery. C Library, Go bindings, Runtime.