
dfir-malware-investigation
Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Proof-of-concept exploit for CVE-2025-64720, a libpng buffer overflow in palette premultiplication. Includes exploit generator, test harness with…

Linux kernel source tree with a targeted patch for CVE-2020-14381, demonstrating a specific kernel vulnerability and its fix for educational…

Educational demonstration of CVE-2023-32784 KeePass master password recovery via memory dump analysis, with step-by-step exploit setup and mitigation…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

Free hands-on digital forensics labs for students and faculty

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

Dumping processes using the power of kernel space !

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

helps visualize heap operations for pwn and debugging


PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

CVE-2026-50416: Windows 11 KASLR bypass