
DetectWindowsCopyOnWriteForAPI
Enumerate various traits from Windows processes as an aid to threat hunting

Enumerate various traits from Windows processes as an aid to threat hunting

Heap analysis tooling for dlmalloc

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking


The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Use CVE-2016-3308 corrupt win32k desktop heap

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver


Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Open source memory scanner written in C++

An Active Defense and EDR software to empower Blue Teams

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…