
volatility3
Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Software sandbox for storage of sensitive information in memory.

A post-exploitation powershell tool for extracting juicy info from memory.

Dump cookies and credentials directly from Chrome/Edge process memory

All reasonably stable tools

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Some of my publicly available Malware analysis and Reverse engineering.


Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)


:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

mXtract - Memory Extractor & Analyzer

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!


Collecting & Hunting for IOCs with gusto and style

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Tools for the Computer Incident Response Team :computer: