
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

ThrottleStop.sys Arbitrary Physical Memory R/W

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Memory API proxy via signed mozglue.dll

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Reflective PE packer.

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)


Generate Payloads and Control Remote Machines. [Discontinued]