
EtwLeakKernel
Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Volatility plugin to extract X screenshots from a memory dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

A tiny cpp program to test reading memory using a vulnerable RTCore64.sys driver/device (CVE-2019-16098). It tries to read a "secret" from its own…

The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to…

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Adobe Reader DC Information Leak Exploit

A Linux version of the ProcDump Sysinternals tool

Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

Android 14 kernel exploit for Pixel7/8 Pro

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Dump LSASS via physical memory read primitives in vulnerable kernel drivers