
Platbox
Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

An automatic unpacker and logger for DotNet Framework targeting files

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Memoro: A Detailed Heap Profiler

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Hide memory artifacts using ROP and hardware breakpoints.

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Process heap analysis framework - Windows/Linux - record type inference and forensics

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Report and exploit of CVE-2023-36427

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall