


Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Spectre exploit

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

The pstrip64.sys kernel driver exposes an IOCTL that allows low-privileged users to map arbitrary ranges of physical memory into their own virtual…

SLUBStick exploitation. Converting a UAF into a cross-cache arbitrary memory R/W primitive through PTE manipulation.

Looking into the memory when sshd 9.1p1 aborts due to a double free bug.

A low pin count sniffer for ICEStick - targeting TPM chips


Scan files or process memory for CobaltStrike beacons and parse their configuration