
PMAT-labs
Labs for Practical Malware Analysis & Triage

Labs for Practical Malware Analysis & Triage

An advanced memory forensics framework

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Repository to index useful tools for CTF's


A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

UNIX-like reverse engineering framework and command-line toolset.

Incident Response & Digital Forensics Debugging Extension

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Program for determining types of files for Windows, Linux and MacOS.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Direct Memory Access (DMA) Attack Software