#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.
DLL-injectable internal game cheat for Plutonium BO2 zombies

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

RAM imaging utility.

Differential Analysis of Malware in Memory

Demonstrates type confusion and heap overflow exploits for CVE-2015-4843 in Java, with demos for aarch64 and Morello, highlighting CHERI capability…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

PoC for CVE-2021-32537: an out-of-bounds memory access that leads to pool corruption in the Windows kernel.

CVE-2020-1206 Uninitialized Kernel Memory Read POC

A forensic evidence collection & analysis toolkit for OS X

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

.NET debugger and assembly editor

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

EDRSandblast-GodFault