


This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

OS X Auditor is a free Mac OS X computer forensics tool

Main repository to pull all NCC Group Cisco ASA-related tool projects.

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs


Hide memory artifacts using ROP and hardware breakpoints.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Poc for CVE-2025-7771 to modify PPL Protection

Windows tool for dumping malware PE files from memory back to disk for analysis.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…