
SuperMem
A python script developed to process Windows memory images based on triage type.

A python script developed to process Windows memory images based on triage type.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Enumerate various traits from Windows processes as an aid to threat hunting

Detect Linux rootkits which use signals to elevate process privileges.

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

the ps utility, with an eBPF twist and container context

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

MagicArch is a comprehensive post-installation script built with Ansible, designed to transform a basic Arch Linux installation into a fully equipped…