
artifacts-kit
Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Use YARA rules on Time Travel Debugging traces

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Proof-of-concept exploit for CVE-2023-20564 demonstrating arbitrary physical memory read/write via AMD Ryzen Master Driver IOCTL handlers, enabling…

on Mac 10.12.2

Kernel memory read exploit leveraging CVE-2013-6282 for local privilege escalation on affected Linux systems.

Example of exploiting CVE-2011-3026 on Firefox (Linux/x86)

Proof-of-concept exploit for CVE-2024-30085, a heap-based buffer overflow in the Windows CLDLFT driver leading to local privilege escalation on…

Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes

Heap overflow exploit for CVE-2021-22555 achieving local privilege escalation to root on Ubuntu 20.04 with kernel 5.8.0-48.

Exploit for CVE-2026-14431 providing V8 sandbox read/write primitives via a crafted JavaScript file, targeting Chromium's V8 engine on Linux x64.

Stack overflow exploit for CVE-2022-0435 in the TIPC module, providing local privilege escalation to root on Ubuntu kernels.

Proof-of-concept exploit for Oracle VirtualBox VGA out-of-bounds read vulnerability, demonstrating address leaking from VirtualBox components on…

OS X Auditor is a free Mac OS X computer forensics tool

Mimikatz implementation in pure Python

Windows tool for dumping malware PE files from memory back to disk for analysis.