
MemITM
Tool to make in memory man in the middle

Tool to make in memory man in the middle

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

All reasonably stable tools

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

OS X Auditor is a free Mac OS X computer forensics tool

Software sandbox for storage of sensitive information in memory.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

tool to extract passwords from TeamViewer memory using Frida

DLL Injection tool to unlock guest VMs

Main repository to pull all NCC Group Cisco ASA-related tool projects.

A little tool to play with the Seclogon service

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Hide memory artifacts using ROP and hardware breakpoints.

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…