
dnSpy
.NET debugger and assembly editor

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

More than a ReClass port to the .NET platform.

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…


Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Use YARA rules on Time Travel Debugging traces

POC for CVE-2018-0824

A Generic Windows Memory Scraping Tool

Java Agent memory horse scanner combined with Call Graph modus

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Golang bindings for PE-sieve