
Learning-Linux-Binary-Analysis
Learning Linux Binary Analysis, published by Packt

Learning Linux Binary Analysis, published by Packt

Process heap analysis framework - Windows/Linux - record type inference and forensics

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

Proof-of-concept for CVE-2023-41992, a macOS kernel vulnerability, demonstrating exploitation techniques and providing a patch analysis.

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

Analysis of VBS exploit CVE-2018-8174

Heap analysis tooling for ptmalloc

Heap analysis tooling for dlmalloc

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…