
analyzer
Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Analysis of VBS exploit CVE-2018-8174

Python exploit tool for CVE-2026-8451 Citrix Netscaler memory overread vulnerability. Generates detection artifacts by leaking memory from target…

Re-implementation of VirtueSecurity's benigncertain-monitor

Retrieve the master password of a keepass database <= 2.53.1

Malware Configuration And Payload Extraction

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Digital forensic acquisition tool for Windows based incident response.


ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.