
BSOD_bitlocker_recover
Python script for carving Bitlocker VMK keys

Python script for carving Bitlocker VMK keys

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Linux Memory Cryptographic Keys Extractor

Hide memory artifacts using ROP and hardware breakpoints.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

DLL Injection tool to unlock guest VMs

A little tool to play with the Seclogon service

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

A Linux version of the ProcDump Sysinternals tool

OS X Auditor is a free Mac OS X computer forensics tool

A post-exploitation powershell tool for extracting juicy info from memory.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

The multi-platform memory acquisition tool.