
memOptix
A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

List of Awesome CobaltStrike Resources

Visualize the virtual address space of a Windows process on a Hilbert curve.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting


RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Dump TeamViewer ID and password from memory. Works much better than other tools.

KeePass 2.X dumper (CVE-2023-32784)

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Retrieve the master password of a keepass database <= 2.53.1

Offline AI Security Assistant for Air-Gapped Pentesting

KeePass Master Password Extraction PoC for Linux

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.