
CVE-2021-45067
Exploit for Adobe Reader DC out-of-bounds read vulnerability (CVE-2021-45067) that leaks sensitive information from the sandboxed process via…

Exploit for Adobe Reader DC out-of-bounds read vulnerability (CVE-2021-45067) that leaks sensitive information from the sandboxed process via…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

A post-exploitation powershell tool for extracting juicy info from memory.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Dump cookies and credentials directly from Chrome/Edge process memory

A low pin count sniffer for ICEStick - targeting TPM chips

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Small toolkit for extracting information and dumping sensitive strings from Windows processes