
moonwalk
find dll base addresses without PEB WALK

find dll base addresses without PEB WALK

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Rebuild of Windows kernel driver functions KeAttachProcess and KeDetachProcess, used for process attachment and anti-cheat bypass research.

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

The PoC of information disclosure in Microsoft Desktop Windows Management.

A revival of the classic and legendary KsDumper

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

All reasonably stable tools

A small utility to deal with malware embedded hashes.

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

Dumping processes using the power of kernel space !

An API hooking framework for intercepting and monitoring Windows applications