
memOptix
A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

GoTEE - example application

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

This is POC for IOS 0click CVE-2025-43300

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

This is POC for IOS 0click CVE-2025-43300

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…


Incident Response Forensic Framework

Process heap analysis framework - Windows/Linux - record type inference and forensics

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…