
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

List of Awesome CobaltStrike Resources

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

A python script developed to process Windows memory images based on triage type.

Example demonstrating a Go-based trusted execution environment on ARM TrustZone and RISC-V, running concurrent unikernels as Trusted OS, Trusted…

A Windows kernel dump C++ parser library with Python 3 bindings.

Toy scripts for playing with WinDbg JS API

Golang bindings for PE-sieve