
vol-rs
Volatility 3 ported to Rust. Same output, much faster.

Volatility 3 ported to Rust. Same output, much faster.

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Scripts for extracting useful information from infected memory dumps

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

A python script developed to process Windows memory images based on triage type.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Contains tools to perform malware and forensic analysis in Memory

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

Integer overflow in FreeType software, which also affects Chrome

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.

This is a workaround for CVE-2014-0993 and CVE-2014-0994 that patches on memory without the need to recompile your vulnerable software. This is not…