
volatility-gui
GUI for Volatility forensics tool written in PyQT5

GUI for Volatility forensics tool written in PyQT5

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

Python script for carving Bitlocker VMK keys

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

The swiss army knife of LSASS dumping


This is the development tree. Production downloads are at:

All reasonably stable tools

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

EDRSandblast-GodFault

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Software sandbox for storage of sensitive information in memory.

Offset Independent Credential Extraction Tool

Finding secrets in kernel and user memory

Utility to find AES keys in running processes

Linux Memory Cryptographic Keys Extractor

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…