
systeminformer
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

An advanced memory forensics framework

Security sensor for realtime threat detection and protection

Volatility 3 ported to Rust. Same output, much faster.

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Ghidra is a software reverse engineering (SRE) framework

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Integer overflow in FreeType software, which also affects Chrome

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Direct Memory Access (DMA) Attack Software

Software sandbox for storage of sensitive information in memory.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…