
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

A python script developed to process Windows memory images based on triage type.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Dump cookies and credentials directly from Chrome/Edge process memory

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

A canary designed to minimize the impact from certain Ransomware actors

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Poc for CVE-2025-7771 to modify PPL Protection

Vulnerability Found on Squid Proxy.

PoC and technical details of CVE-2025-24204

Potential Integer Overflow Leading To Heap Overflow in AMD KFD.