
IRTriage
Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Open source memory scanner written in C++

A post-exploitation powershell tool for extracting juicy info from memory.

Scan files or process memory for CobaltStrike beacons and parse their configuration

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Collection of forensic tools

A Linux version of the ProcDump Sysinternals tool

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

An advanced memory forensics framework

UNIX-like reverse engineering framework and command-line toolset

Enumerate various traits from Windows processes as an aid to threat hunting

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Dump TeamViewer ID and password from memory. Works much better than other tools.

CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.

Re-implementation of VirtueSecurity's benigncertain-monitor