
VMInjector
DLL Injection tool to unlock guest VMs

DLL Injection tool to unlock guest VMs

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

A Runtime Crypter in C for Linux ELF binaries.

Hide memory artifacts using ROP and hardware breakpoints.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

A little tool to play with the Seclogon service

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A post-exploitation powershell tool for extracting juicy info from memory.

A Linux version of the ProcDump Sysinternals tool

OS X Auditor is a free Mac OS X computer forensics tool

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…