


A memory-based evasion technique which makes shellcode invisible from process start to end.

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

A Generic Windows Memory Scraping Tool

PoC for CVE-2026-2005

GoTEE - example application

CVE-2026-5201: Heap-based buffer overflow in gdk-pixbuf JPEG loader (CWE-122, CVSS 7.5)

Dynamic unpacker based on PE-sieve

mXtract - Memory Extractor & Analyzer

Linux Memory Cryptographic Keys Extractor

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…