
ComfyEngine
ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Volatility plugin to extract X screenshots from a memory dump

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

Poc for CVE-2025-7771 to modify PPL Protection

Contains tools to perform malware and forensic analysis in Memory

Old CVE, but new way to leak everything.

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

RAMnesia Attack: A Scientific Investigation of WireTap Threats to Bitcoin Infrastructure, Hardware Vulnerabilities (CVE-2025-6202, CVE-2023-39910),…

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

Looking into the memory when sshd 9.1p1 aborts due to a double free bug.

By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this…

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…