
PPLBlade
Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Old CVE, but new way to leak everything.

Exploit for Adobe Reader DC out-of-bounds read vulnerability (CVE-2021-45067) that leaks sensitive information from the sandboxed process via…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…


Dump cookies and credentials directly from Chrome/Edge process memory

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

A low pin count sniffer for ICEStick - targeting TPM chips

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Windows research PoC in C that scans Microsoft Edge process memory for credential-related data, with a standalone executable and a BOF variant for C2…

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

Simple Process Dumper using DMA over a PCIe FPGA device