


All reasonably stable tools

An Active Defense and EDR software to empower Blue Teams

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Windows Analysis and Research Toolkit


mXtract - Memory Extractor & Analyzer

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

SALT - SLUB ALlocator Tracer for the Linux kernel



Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.


CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)