
mnemosyne
A Generic Windows Memory Scraping Tool

A Generic Windows Memory Scraping Tool

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Executes at the silicon boundary

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

xnu kernel heap info leak

POC for CVE-2015-6620, AMessage unmarshal arbitrary write

CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.

Proof-of-concept exploit for CVE-2022-26717, a use-after-free vulnerability in Safari's WebGL implementation, enabling remote code execution via…

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)

Memory API proxy via signed mozglue.dll

Java Agent memory horse scanner combined with Call Graph modus

PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

Volatility plugin to extract X screenshots from a memory dump

PoC for CVE-2019-0888 - Use-After-Free in Windows ActiveX Data Objects (ADO)

CVE-2014-4321 exploit

GUI for Volatility forensics tool written in PyQT5