
PyMemoryEditor
A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Mimikatz implementation in pure Python

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A python script developed to process Windows memory images based on triage type.

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

A Windows kernel dump C++ parser library with Python 3 bindings.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Process heap analysis framework - Windows/Linux - record type inference and forensics

Python script for carving Bitlocker VMK keys

libtalloc is a python script for use with GDB that can be used to analyse the "trivial allocator" (talloc)

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Python 2.7.14 race condition UAF proof-of-concept