

A forensic evidence collection & analysis toolkit for OS X

OS X Auditor is a free Mac OS X computer forensics tool

Incident Response Forensic Framework

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A low pin count sniffer for ICEStick - targeting TPM chips

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…



Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7


Distributed & real time digital forensics at the speed of the cloud

CVE-2018-4343: Proof-of-concept for a use-after-free in the GSSCred daemon on macOS and iOS.

CVE-2025-43300: iOS/macOS DNG Image Processing Memory Corruption

Software sandbox for storage of sensitive information in memory.

Exploit for CVE-2021-30807