
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

DLL Injection tool to unlock guest VMs

Tool to make in memory man in the middle

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

A forensic evidence collection & analysis toolkit for OS X

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

OS X Auditor is a free Mac OS X computer forensics tool

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…


A PoC Java Stager which can download, compile, and execute a Java file in memory.

A Runtime Crypter in C for Linux ELF binaries.