
pypykatz
Mimikatz implementation in pure Python

Mimikatz implementation in pure Python

Python script for carving Bitlocker VMK keys

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.


Digital forensic acquisition tool for Windows based incident response.

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

EDRSandblast-GodFault

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

GUI for Volatility forensics tool written in PyQT5

OS X Auditor is a free Mac OS X computer forensics tool

Tool to make in memory man in the middle

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…