#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.
Technical analysis and proof-of-concept for CVE-2018-8389, a use-after-free vulnerability in Internet Explorer's jscript.dll allowing remote code…

CVE-2021-38304 Proof of Concept

Linux kernel 4.19.72 with a targeted patch or exploit for CVE-2022-29581, demonstrating a specific kernel vulnerability for security research and…

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

CVE-2024-3094

Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)

Microsoft HEIF Extension (msheif_store.dll) OOB-read

Re-write of original KeePass 2.X Master Password Dumper (CVE-2023-32784) POC in python.

By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this…

TryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts

Technical analysis and proof-of-concept for CVE-2017-16943, a use-after-free in Exim's receive_msg function, demonstrating heap manipulation and RIP…

C library for stack unwinding and backtrace generation, supporting multiple architectures and operating systems, with build and regression testing…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Scripts for extracting useful information from infected memory dumps

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

ESF modular ingestion tool for development and research.