
DIRT
Driver Initial Reconnaissance Tool

Driver Initial Reconnaissance Tool

PunkBuster LPI to NT AUTHORITY\SYSTEM

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures.

SASM - simple crossplatform IDE for NASM, MASM, GAS and FASM assembly languages

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

All reasonably stable tools

The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based…

Kernel pointers copied to output user mode buffer with ioctl 0x22A014 in the appid.sys driver.

Proof-of-concept for CVE-2018-9950, an out-of-bounds read vulnerability in Foxit Reader/PhantomPDF leading to information disclosure and potential…

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read

This script can help determine the CPU ID for the processor of your system, please note that I have not added every CPU ID to this script, edit as…

Kernel Stack info leak at exportObjectToClient function

Analyze and demonstrate the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software on gaming laptops, with automated…

CVE-2020-25578 and CVE-2020-25579: Some FreeBSD info leak bugs I found in 2020.

Integer overflow in Oniguruma

The PoC of information disclosure in Microsoft Desktop Windows Management.