
digital-forensics-lab
Free hands-on digital forensics labs for students and faculty
ai-securityctfdigital-forensics+9
3.0k

Free hands-on digital forensics labs for students and faculty

A post-exploitation powershell tool for extracting juicy info from memory.

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…