#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Enumerate various traits from Windows processes as an aid to threat hunting

Toy scripts for playing with WinDbg JS API

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Tool to make in memory man in the middle

Proof of concept & details for CVE-2025-21298

Hide memory artifacts using ROP and hardware breakpoints.

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

BOF to run PE in Cobalt Strike Beacon without console creation

.NET runtime inspector

A generic game/software hacking tool written from the ground up in Rust.

Lenovo Diagnostics Driver EoP - Arbitrary R/W

Linux Evidence Acquisition Framework

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。