
LaZagne
Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Mimikatz implementation in pure Python

OS X Auditor is a free Mac OS X computer forensics tool

Utility to find AES keys in running processes

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

tool to extract passwords from TeamViewer memory using Frida

Digital forensic acquisition tool for Windows based incident response.

EDRSandblast-GodFault

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Tool to make in memory man in the middle


Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

GUI for Volatility forensics tool written in PyQT5

Python script for carving Bitlocker VMK keys