
keepass-exfil-forensics
Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Dump cookies and credentials directly from Chrome/Edge process memory

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…




CitrixBleed2 poc

My experiments in weaponizing Nim (https://nim-lang.org/)

High speed/Low cost CommonCrawl RegExp in Node.js

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Adobe Reader DC Information Leak Exploit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…