
CobaltStrikeScan
Scan files or process memory for CobaltStrike beacons and parse their configuration

Scan files or process memory for CobaltStrike beacons and parse their configuration

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Script for automating Linux memory capture and analysis

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Windows Analysis and Research Toolkit

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A revival of the classic and legendary KsDumper

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

memory search and patch tool on debuggable apk without root & ndk

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

Curated guide to becoming a malware analyst, covering essential knowledge, reverse engineering, analysis tools, and LLM-assisted learning with…