


IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Extract Windows credentials directly from VM memory snapshots and virtual disks

Collection of forensic tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

The multi-platform memory acquisition tool.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Live hunting of code injection techniques

Incident Response Forensic Framework

Script for automating Linux memory capture and analysis

Digital forensic acquisition tool for Windows based incident response.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

Automagically extract forensic timeline from volatile memory dump

CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A Windows kernel dump C++ parser library with Python 3 bindings.