
VMkatz
Extract Windows credentials directly from VM memory snapshots and virtual disks

Extract Windows credentials directly from VM memory snapshots and virtual disks

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

tool to extract passwords from TeamViewer memory using Frida

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…


This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Automagically extract forensic timeline from volatile memory dump

Finding secrets in kernel and user memory


Volatility plugin to extract X screenshots from a memory dump


a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Walk x86-64 page tables by hand in qemu and gdb. Decompose a virtual address, follow cr3 through all levels of physical memory, and extract a flag…

Python script for carving Bitlocker VMK keys

on Mac 10.12.2