
x64dbg
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

All reasonably stable tools

UNIX-like reverse engineering framework and command-line toolset

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Dumping processes using the power of kernel space !

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).


PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…