- Darksurgeon: https://github.com/cryps1s/DARKSURGEON
- APT Simulator : https://github.com/NextronSystems/APTSimulator
- Caldera (MITRE): https://github.com/mitre/caldera
- Invoke-Adversary : https://github.com/CyberMonitor/Invoke-Adversary
- RTA : https://github.com/endgameinc/RTA
- MalwLess : https://github.com/n0dec/MalwLess
- BitLocker mount (Linux): https://github.com/libyal/libbde
- psinfo plugin for Volatility (advanced process information from VAT / PEB): https://github.com/monnappa22/Psinfo
- bitlocker pluging for Volatility to extract key from memory: https://github.com/elceef/bitlocker
- WinDBG debugger extension to trace data flow backwards through the control flow of a function https://github.com/Microsoft/WinDbg-Samples/tree/master/CodeFlow