
Filedumper
Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Virtual Machine Introspection, Tracing & Debugging

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A python script developed to process Windows memory images based on triage type.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

Enumerate various traits from Windows processes as an aid to threat hunting

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Visualize the virtual address space of a Windows process on a Hilbert curve.