
TuxResponse
Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.


RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Web-based Yara rule debugger with an editor, live match evaluation, matched-string details, and rule dependency visualization for detection…

HexaLocker ransomware analysis

Live hunting of code injection techniques

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

Digital Forensics Intelligence Framework

Live Hidden Camera is a library which record live video and audio from Android device without displaying a preview.

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…