
SuperMem
A python script developed to process Windows memory images based on triage type.

A python script developed to process Windows memory images based on triage type.

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

An Active Defense and EDR software to empower Blue Teams

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server…

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Windows tool for dumping malware PE files from memory back to disk for analysis.

Code Injection, Inject malicious payload via pagetables pml4.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Contains tools to perform malware and forensic analysis in Memory

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

volatility explorer (volatility 2)

Volatility Explorer Suit (volatility 3)

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…