
DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

SALT - SLUB ALlocator Tracer for the Linux kernel

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

All reasonably stable tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Dumping processes using the power of kernel space !

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.