
PyMemoryEditor
A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

All reasonably stable tools

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Dump cookies and credentials directly from Chrome/Edge process memory

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

Vulnerability Found on Squid Proxy.

Poc for CVE-2025-7771 to modify PPL Protection

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

PoC and technical details of CVE-2025-24204

A revival of the classic and legendary KsDumper

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

The swiss army knife of LSASS dumping