
wmi-static-spoofer
Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

tool to extract passwords from TeamViewer memory using Frida

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Grab ssh keys from ssh-agent

Enumerate various traits from Windows processes as an aid to threat hunting

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

Automagically extract forensic timeline from volatile memory dump

A generic game/software hacking tool written from the ground up in Rust.

Dump TeamViewer ID and password from memory. Works much better than other tools.

A canary designed to minimize the impact from certain Ransomware actors

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Small toolkit for extracting information and dumping sensitive strings from Windows processes

GPG Reaper - Obtain/Steal/Restore GPG Private Keys from gpg-agent cache/memory

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.