
pcileech
Direct Memory Access (DMA) Attack Software

Direct Memory Access (DMA) Attack Software

The swiss army knife of LSASS dumping

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Utility to find AES keys in running processes

Meltdown Exploit PoC

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Linux Memory Cryptographic Keys Extractor

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day


Finding secrets in kernel and user memory

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…