
PyMemoryEditor
A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

KeePass 2.X dumper (CVE-2023-32784)

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

An advanced memory forensics framework

Mimikatz implementation in pure Python

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

Volatility 3 ported to Rust. Same output, much faster.

Re-write of original KeePass 2.X Master Password Dumper (CVE-2023-32784) POC in python.

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Python script for carving Bitlocker VMK keys

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Volatility plugin for extracts configuration data of known malware