
memhunter
Live hunting of code injection techniques

Live hunting of code injection techniques

Dumping processes using the power of kernel space !

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A curated collection of DFIR skills and workflows for InfoSec practitioners.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Proof of concept & details for CVE-2025-21298

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Visualize the virtual address space of a Windows process on a Hilbert curve.

Report and exploit of CVE-2023-36427

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

PoC and technical details of CVE-2025-24204

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections