
hollows_hunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…
defensive-toolsforensicsincident-response+2
2.4k

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Finding secrets in kernel and user memory

Ghidra is a software reverse engineering (SRE) framework