
systeminformer
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

SALT - SLUB ALlocator Tracer for the Linux kernel


Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

All reasonably stable tools

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).


The multi-platform memory acquisition tool.

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

A memory-based evasion technique which makes shellcode invisible from process start to end.

This is the development tree. Production downloads are at:


Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

A Linux version of the ProcDump Sysinternals tool