
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Old CVE, but new way to leak everything.

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Dump cookies and credentials directly from Chrome/Edge process memory


CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Adobe Reader DC Information Leak Exploit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

A low pin count sniffer for ICEStick - targeting TPM chips
