
DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

SALT - SLUB ALlocator Tracer for the Linux kernel

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

All reasonably stable tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…