
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Free hands-on digital forensics labs for students and faculty

Security sensor for realtime threat detection and protection

Easy-to-use live forensics toolbox for Linux endpoints

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.


Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Defund the Police.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

List of Awesome CobaltStrike Resources

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Malware Configuration And Payload Extraction
