

More than a ReClass port to the .NET platform.

BOF to run PE in Cobalt Strike Beacon without console creation

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Windows tool for dumping malware PE files from memory back to disk for analysis.

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

tool to extract passwords from TeamViewer memory using Frida

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A little tool to play with the Seclogon service

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Using CVE-2023-21768 to manual map kernel mode driver