
CVE-2023-32784-kdbxpassdmp
Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

List of Awesome CobaltStrike Resources

Visualize the virtual address space of a Windows process on a Hilbert curve.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting


RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Dump TeamViewer ID and password from memory. Works much better than other tools.

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

KeePass 2.X dumper (CVE-2023-32784)

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Extracts KeePass master passwords from memory dumps of unlocked databases, outputting potential characters by position, a passphrase, and a…

Retrieve the master password of a keepass database <= 2.53.1

Offline AI Security Assistant for Air-Gapped Pentesting