
ForensicMiner
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

UNIX-like reverse engineering framework and command-line toolset

Mimikatz implementation in pure Python

writeup of CVE-2020-1362

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A PoC Java Stager which can download, compile, and execute a Java file in memory.

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Golang bindings for PE-sieve


Critical use-after-free vulnerability discovered in Tinyproxy

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Grab ssh keys from ssh-agent

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.