#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

A BOF designed to inspect processes memory and addresses

General malware analysis stuff

Client-server tool for live data collection during incident response. Admin sends requests to clients to gather system information for forensic…

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

这里保留着部分脏牛漏洞的利用代码

Exploit for AMD SEV-SNP firmware vulnerability (CVE-2023-31355) that decrypts arbitrary memory of decommissioned guests by corrupting the UMC key…

Kernel memory read exploit leveraging CVE-2013-6282 for local privilege escalation on affected Linux systems.

Potential Integer Overflow Leading To Heap Overflow in AMD KFD.

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

CVE-2020-25578 and CVE-2020-25579: Some FreeBSD info leak bugs I found in 2020.

Proof-of-concept exploit for CVE-2024-30085, a heap-based buffer overflow in the Windows CLDLFT driver leading to local privilege escalation on…

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity