
dfirtriage
Digital forensic acquisition tool for Windows based incident response.

Digital forensic acquisition tool for Windows based incident response.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

PoC for CVE-2026-2005

Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087…

Dump cookies and credentials directly from Chrome/Edge process memory

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A memory-based evasion technique which makes shellcode invisible from process start to end.

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Runs packed malware in a controlled environment, waits for self-unpacking, dumps PE files and shellcodes from memory, and terminates the process.

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.