
dnSpy
.NET debugger and assembly editor

Scan files or process memory for CobaltStrike beacons and parse their configuration

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A low pin count sniffer for ICEStick - targeting TPM chips

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

Spectre exploit

The pstrip64.sys kernel driver exposes an IOCTL that allows low-privileged users to map arbitrary ranges of physical memory into their own virtual…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Looking into the memory when sshd 9.1p1 aborts due to a double free bug.

SLUBStick exploitation. Converting a UAF into a cross-cache arbitrary memory R/W primitive through PTE manipulation.
