
forensictools
Collection of forensic tools

Collection of forensic tools

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

A centralized and enhanced memory analysis platform

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Digital forensic acquisition tool for Windows based incident response.

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…


Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

List of Awesome CobaltStrike Resources

An advanced memory forensics framework

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…