
CVE-2017-12561
Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and…

Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and…

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

Volatility 3 ported to Rust. Same output, much faster.

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Scripts for extracting useful information from infected memory dumps

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A python script developed to process Windows memory images based on triage type.

A Windows kernel dump C++ parser library with Python 3 bindings.

Windows Analysis and Research Toolkit

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

A canary designed to minimize the impact from certain Ransomware actors

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Contains tools to perform malware and forensic analysis in Memory