
linux-copy-fail-CVE-2026-31431
Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Python script for carving Bitlocker VMK keys

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

CVE-2025-14847 (MongoBleed)

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

A python script developed to process Windows memory images based on triage type.

Retrieve the master password of a keepass database <= 2.53.1

Heap analysis tooling for dlmalloc

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

Grab ssh keys from ssh-agent