

Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

UNIX-like reverse engineering framework and command-line toolset

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

You didn't think I'd go and leave the blue team out, right?

A Linux version of the ProcDump Sysinternals tool

Malware Configuration And Payload Extraction

GoTEE - example application

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

DLL-injectable internal game cheat for Plutonium BO2 zombies

Volatility 3 ported to Rust. Same output, much faster.

SLUBStick exploitation of CVE-2022-2588. Converting a DF into a cross-cache arbitrary memory R/W primitive through PTE manipulation.


Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Collection of forensic tools