
volatility3
Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

An advanced memory forensics framework


Volatility 3 ported to Rust. Same output, much faster.

Process heap analysis framework - Windows/Linux - record type inference and forensics

A powerful and user-friendly binary analysis platform!

Ghidra is a software reverse engineering (SRE) framework

UNIX-like reverse engineering framework and command-line toolset

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

An automatic unpacker and logger for DotNet Framework targeting files

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…


Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Incident Response Forensic Framework

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…