
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

List of Awesome CobaltStrike Resources

Toy scripts for playing with WinDbg JS API

Golang bindings for PE-sieve


Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A canary designed to minimize the impact from certain Ransomware actors

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)


Research project related to memory address analysis

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Experimental Windows .text section Patch Detector