
fibratus
Security sensor for realtime threat detection and protection

Security sensor for realtime threat detection and protection

OS X Auditor is a free Mac OS X computer forensics tool

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.


IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Mimikatz implementation in pure Python

Meltdown Exploit PoC

This is the development tree. Production downloads are at:

Utility to find AES keys in running processes

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

A PowerShell Module Dedicated to Reverse Engineering

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

The swiss army knife of LSASS dumping

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.