
vol-rs
Volatility 3 ported to Rust. Same output, much faster.

Volatility 3 ported to Rust. Same output, much faster.

GoTEE - example application

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

ROP-based sleep obfuscation to evade memory scanners

An advanced memory forensics framework

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567


CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…