
CVE-2026-46215-exploit-linux-7.0-uaf-stable
CVE-2026-46215 DRM GEM UAF Exploit for Linux 7.0 - The first working PoC for linux kernel 7 use after free- by Antonius (sw0rdm4n, w1sdom, ev1lut10n)

CVE-2026-46215 DRM GEM UAF Exploit for Linux 7.0 - The first working PoC for linux kernel 7 use after free- by Antonius (sw0rdm4n, w1sdom, ev1lut10n)

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Original PoC for CVE-2023-32784

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Script for automating Linux memory capture and analysis

Linux kernel use-after-free (UAF) privilege escalation exploit for CVE-2018-17182, providing root shell access on affected kernels (3.16 to 4.18.8).…

Digital forensic acquisition tool for Windows based incident response.

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.