
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Dump cookies and credentials directly from Chrome/Edge process memory

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

A lightweight dynamic instrumentation library

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

An API hooking framework for intercepting and monitoring Windows applications

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Drltrace is a library calls tracer for Windows and Linux applications.

All reasonably stable tools

A dynamic VMP dumper and import fixer, powered by VTIL.