
frida-dexdump
A frida tool to dump dex in memory to support security engineers analyzing malware.

A frida tool to dump dex in memory to support security engineers analyzing malware.

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Direct Memory Access (DMA) Attack Software

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

OS X Auditor is a free Mac OS X computer forensics tool

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)


UAFuzz: Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities

Grab ssh keys from ssh-agent

Lenovo Diagnostics Driver EoP - Arbitrary R/W


针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Hide memory artifacts using ROP and hardware breakpoints.
