
ir-rescue
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

A python script developed to process Windows memory images based on triage type.

CVE-2025-14847 (MongoBleed)

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

Retrieve the master password of a keepass database <= 2.53.1

Grab ssh keys from ssh-agent

Heap analysis tooling for dlmalloc


Script for automating Linux memory capture and analysis

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Python script for carving Bitlocker VMK keys

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A forensic evidence collection & analysis toolkit for OS X