
PyMemoryEditor
A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Collecting & Hunting for IOCs with gusto and style

helps visualize heap operations for pwn and debugging

Linux kernel use-after-free (UAF) privilege escalation exploit for CVE-2018-17182, providing root shell access on affected kernels (3.16 to 4.18.8).…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

An automatic unpacker and logger for DotNet Framework targeting files