
OSXAuditor
OS X Auditor is a free Mac OS X computer forensics tool

OS X Auditor is a free Mac OS X computer forensics tool

Tool to make in memory man in the middle

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Python script for carving Bitlocker VMK keys

Panic button for protection against cold boot attacks

tool to extract passwords from TeamViewer memory using Frida

DLL Injection tool to unlock guest VMs

A little tool to play with the Seclogon service

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

A frida tool to dump dex in memory to support security engineers analyzing malware.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

SALT - SLUB ALlocator Tracer for the Linux kernel

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Educational research tool demonstrating CVE-2025-14847 memory disclosure in MongoDB's BSON decompression. Simulates bounds-checking failures and…