
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Dump cookies and credentials directly from Chrome/Edge process memory

A memory-based evasion technique which makes shellcode invisible from process start to end.

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

mXtract - Memory Extractor & Analyzer

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Digital forensic acquisition tool for Windows based incident response.

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

A python script developed to process Windows memory images based on triage type.

Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087…

Linux Memory Cryptographic Keys Extractor

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Using CVE-2023-21768 to manual map kernel mode driver