
volatility3
Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Some of my publicly available Malware analysis and Reverse engineering.

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

A centralized and enhanced memory analysis platform

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Script for automating Linux memory capture and analysis

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Windows Analysis and Research Toolkit

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.