
OnTheEdge
Windows research PoC in C that scans Microsoft Edge process memory for credential-related data, with a standalone executable and a BOF variant for C2…

Windows research PoC in C that scans Microsoft Edge process memory for credential-related data, with a standalone executable and a BOF variant for C2…

Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in…


Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Finding secrets in kernel and user memory

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Utility to find AES keys in running processes

A memory-based evasion technique which makes shellcode invisible from process start to end.

SALT - SLUB ALlocator Tracer for the Linux kernel

Memoro: A Detailed Heap Profiler

Volatility 3 ported to Rust. Same output, much faster.

PoC and technical details of CVE-2025-24204

Python script for carving Bitlocker VMK keys

A Runtime Crypter in C for Linux ELF binaries.

Experimental Windows .text section Patch Detector

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

CVE-2025-14847 (MongoBleed)