ctypeslib. Generate python ctypes classes from C headers. Requires LLVM clang
245sslsnoop. Live SSH/SSL/TLS decryption - extraction of secret keys from live process memory
110python-haystack. Process heap analysis framework - Windows/Linux - record type inference and forensics
95python-clang. Python bindings for clang from clang HEAD
45python-cymru-services. API to use Cymru services
27phash-graph-mvp. Graph a MVP tree from pHash
20unhooker. ps fun
7python3-adns. adns-python port to python3
6ctypes-kernel. python-haystack extensions for kernel structures
5bcdedit. BCD editor - Windows Boot Configuration Data
5theta. Ricoh Theta Unity firmware deobfuscation
5django-mantis. A Framework for managing Cyber Threat Intelligence.
4LogRhythmHuntingApp. Python
4python-haystack-reverse. Memory forensics data structure reversing
3fetch-taleo.
3libheap. python library for examining the glibc heap
3http-brute-random-uuid-param. Nmap NSE script that try to brute a uuid param using random uuid generation
3pastemon. pastebin.com Content Monitoring Tool
3django-unicorn-filteredpaginatedview-example. A example of a django-unicorn filtered and paginated view
2ingresstools. Python
2heaper. heaper, an advanced heap analysis plugin for Immunity Debugger
2oraclehash. Oracle Database hash generator
2phash-play. Shell
2tcpflow-http-extract. extract http content from tcpflow
2canalplus. Python
2clang. Clang Head
1canari3. Canari v3 - next gen Maltego framework for rapid remote and local transform development
1fexml2stix. exports FireEye (CMS) alerts to STIX and malware object to Viper storage
1skypeopensource. skype open source
1pdbparse. pdbparse patches
1cuckoo. Cuckoo Sandbox is an automated dynamic malware analysis system
1cvelib. A Python library and command line interface for CVE Services.
1AIL-framework. AIL framework - Analysis Information Leak framework
1Responder. Responder is a LLMNR and NBT-NS poisoner, with built-in HTTP/SMB/MSSQL/FTP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
1slides. A slide presentation framework in HTML, JS, and OOCSS
1AndrewSpecial. AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.
1cuckoo-memdump. cuckoo-memdump
1deobfuscate. deobfuscate
1rtti-helper-scripts. A few IDAPython scripts to generate class hierarchy diagrams from IDBs
1community. Volatility plugins developed and maintained by the community
1viper. Binary analysis framework
1Cortex4py. Python API Client for Cortex
1cypherhound. Python3 terminal application that contains 400 Neo4j cyphers for BloodHound data sets and 383 GUI cyphers
1NetworkTools. Some helper tools for network pentest
1rdap. python rdap client
1metasploit-framework. Metasploit Framework
1dns-exfiltration. Exfiltrate files via DNS
1python-haystack-gui. GUI for Python-haystack
1gaphor. Gaphor is a UML modelling tool written in Python
1DFTP. Python DNS Exfiltration Tool - Domain Name Service File Transfer Protocol (DFTP) Client and Server. TODO: Integrate Lexer, Parser instead of split()
1ruby-haystack. haystack port to ruby. pitfall to ruby-ffi : 1) the generator outputs :pointer types which is basically equivalent to a void_ptr instead of a type_ptr . We cannot do automatic pointer type resolution.
1ctypes-libqt. libqt python ctypes structure generated by ctypeslib
1mguesser. mguesser guesses a text language
1pHash. Github-Repository of the pHash.org library for perceptual hashing.
1