
clairvoyance
Visualize the virtual address space of a Windows process on a Hilbert curve.

Visualize the virtual address space of a Windows process on a Hilbert curve.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Retrieve the master password of a keepass database <= 2.53.1

Differential Analysis of Malware in Memory

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Digital forensic acquisition tool for Windows based incident response.

Enumerate various traits from Windows processes as an aid to threat hunting

Volatility plugin to extract X screenshots from a memory dump

KeePass 2.X dumper (CVE-2023-32784)

KeePass Master Password Extraction PoC for Linux

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…
