
bulk_extractor
This is the development tree. Production downloads are at:

This is the development tree. Production downloads are at:

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

An Active Defense and EDR software to empower Blue Teams

A Runtime Crypter in C for Linux ELF binaries.


Python script for carving Bitlocker VMK keys

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Poc for CVE-2025-7771 to modify PPL Protection

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…