
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis
"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Enumerate various traits from Windows processes as an aid to threat hunting

Heap analysis tooling for dlmalloc

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking


The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

Use CVE-2016-3308 corrupt win32k desktop heap

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver


Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…