
ATMMalScan
Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

GUI for Volatility forensics tool written in PyQT5

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

A frida tool to dump dex in memory to support security engineers analyzing malware.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Penetration testing utility and antivirus assessment tool.

Finding secrets in kernel and user memory

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

This is the development tree. Production downloads are at:

Memory Debugger for Windows, Linux, Mac, and Android

The swiss army knife of LSASS dumping