
GhostTrace
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Memory Debugger for Windows, Linux, Mac, and Android

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Yet Another Memory Analyzer for malware detection

Small toolkit for extracting information and dumping sensitive strings from Windows processes

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…