
cortex
A Windows runtime analysis toolkit combining memory scanning, debugging, automation, and AI-friendly APIs.

A Windows runtime analysis toolkit combining memory scanning, debugging, automation, and AI-friendly APIs.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Malware Configuration And Payload Extraction

Distributed & real time digital forensics at the speed of the cloud

An Active Defense and EDR software to empower Blue Teams

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

A generic game/software hacking tool written from the ground up in Rust.

A PoC Java Stager which can download, compile, and execute a Java file in memory.

linux security checks

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Golang bindings for PE-sieve

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…