
LaZagne
Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

An Active Defense and EDR software to empower Blue Teams

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Open source memory scanner written in C++

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Enumerate various traits from Windows processes as an aid to threat hunting

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Heap analysis tooling for dlmalloc

CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)