
rip_raw
Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Digital forensic acquisition tool for Windows based incident response.

Enumerate various traits from Windows processes as an aid to threat hunting


Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Scan files or process memory for CobaltStrike beacons and parse their configuration

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Visualize the virtual address space of a Windows process on a Hilbert curve.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Dump TeamViewer ID and password from memory. Works much better than other tools.

Small toolkit for extracting information and dumping sensitive strings from Windows processes

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Retrieve the master password of a keepass database <= 2.53.1


mXtract - Memory Extractor & Analyzer

Volatility plugin to extract X screenshots from a memory dump