
LiME
Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

A canary designed to minimize the impact from certain Ransomware actors

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Rust-based PoC exploit for CVE-2025-7771 providing arbitrary read/write primitives via a vulnerable driver, with virtual-to-physical address…

Educational Python model demonstrating a Use-After-Free (UAF) privilege escalation vulnerability inspired by CVE-2025-30400 in Windows DWM. Simulates…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

SALT - SLUB ALlocator Tracer for the Linux kernel

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

Exploit and research repository analyzing CVE-2025-60013, a critical HSM initialization vulnerability enabling Bitcoin private key recovery via…

Penetration testing utility and antivirus assessment tool.

Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Security sensor for realtime threat detection and protection

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Extract Windows credentials directly from VM memory snapshots and virtual disks