
drmemory
Memory Debugger for Windows, Linux, Mac, and Android

Memory Debugger for Windows, Linux, Mac, and Android

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Windows memory hacking library

A Generic Windows Memory Scraping Tool

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Tool to make in memory man in the middle

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Open source memory scanner written in C++

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

Unsigned Kernel Mode Driver that does memory modifications

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

Proof-of-concept exploit for CVE-2022-21971, an uninitialized pointer free vulnerability in Windows Runtime's prauthproviders.dll, triggered via…


PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"