
volatility
An advanced memory forensics framework

An advanced memory forensics framework

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Collection of forensic tools

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

A centralized and enhanced memory analysis platform

List of Awesome CobaltStrike Resources

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Enumerate various traits from Windows processes as an aid to threat hunting

Dump TeamViewer ID and password from memory. Works much better than other tools.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Retrieve the master password of a keepass database <= 2.53.1

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…