
PSI_BOF
A BOF designed to inspect processes memory and addresses

A BOF designed to inspect processes memory and addresses

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

List of Awesome CobaltStrike Resources

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…


Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

A host based IDS written in C# Targetted at Metasploit

Proof-of-concept exploit for Oracle VirtualBox VGA out-of-bounds read vulnerability, demonstrating address leaking from VirtualBox components on…

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

A post-exploitation powershell tool for extracting juicy info from memory.

More than a ReClass port to the .NET platform.

Extract Windows credentials directly from VM memory snapshots and virtual disks