
aes-finder
Utility to find AES keys in running processes

Utility to find AES keys in running processes

A memory-based evasion technique which makes shellcode invisible from process start to end.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

The multi-platform memory acquisition tool.

Digital forensic acquisition tool for Windows based incident response.

Exploit tool leveraging CVE-2020-12928 (AMD RyzenMaster driver) for game memory manipulation and anti-cheat bypass on Windows 10 with AMD Ryzen CPUs.


Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

A Generic Windows Memory Scraping Tool

GUI for Volatility forensics tool written in PyQT5

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

Exploit for AMD SEV-SNP firmware vulnerability (CVE-2023-31355) that decrypts arbitrary memory of decommissioned guests by corrupting the UMC key…


This is the development tree. Production downloads are at:

The swiss army knife of LSASS dumping


Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes