
volatility-plugins
Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

Scripts for extracting useful information from infected memory dumps

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

RAM imaging utility.

Easy-to-use live forensics toolbox for Linux endpoints

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"



EDRSandblast-GodFault

PoC for CVE-2021-32537: an out-of-bounds memory access that leads to pool corruption in the Windows kernel.

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

A frida tool to dump dex in memory to support security engineers analyzing malware.

CVE-2020-1206 Uninitialized Kernel Memory Read POC