
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.


Dump cookies and credentials directly from Chrome/Edge process memory

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Enumerate various traits from Windows processes as an aid to threat hunting

A canary designed to minimize the impact from certain Ransomware actors

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Android 14 kernel exploit for Pixel7/8 Pro

Dump TeamViewer ID and password from memory. Works much better than other tools.

tool to extract passwords from TeamViewer memory using Frida

A low pin count sniffer for ICEStick - targeting TPM chips