
flare-vm
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

An Active Defense and EDR software to empower Blue Teams

A python script developed to process Windows memory images based on triage type.

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Direct Memory Access (DMA) Attack Software

Windows tool for dumping malware PE files from memory back to disk for analysis.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Windows kernel driver experiment based on KasperskyHook that uses direct syscalls for interprocess memory copying, with support for unloading the…

Volatility 3 ported to Rust. Same output, much faster.

volatility explorer (volatility 2)