
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

List of Awesome CobaltStrike Resources

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

Toy scripts for playing with WinDbg JS API

Golang bindings for PE-sieve

Use YARA rules on Time Travel Debugging traces


QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.


Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.


Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

A Generic Windows Memory Scraping Tool

on Mac 10.12.2

This is the development tree. Production downloads are at: