ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again. Another way to make an LKM visible is using the imperius trick: https://github.com/MatheuZSecurity/Imperius …


ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again. Another way to make an LKM visible is using the imperius trick: https://github.com/MatheuZSecurity/Imperius …

VolWeb is a digital forensic memory analysis platform that leverages the power of the Volatility 3 framework. It is dedicated …
DOUGLAS-042 stands as an ingenious embodiment of a PowerShell script meticulously designed to expedite the triage process and facilitate the …
Motivation During the forensic analysis of a Windows machine, you may find the name of a deleted prefetch file. While …
FACT is a tool to collect, process and visualise forensic data from clusters of machines running in the cloud or …
A PowerShell script to collect memory and (triage) disk forensics for incident response investigations. The script leverages a network share, …
r2 is a rewrite from scratch of radare. It provies a set of libraries, tools and plugins to ease reverse …
LabCIF – Forensic Analysis for Mobile Apps Getting Started Android extraction and analysis framework with an integrated Autopsy Module. Dump …