
DetectWindowsCopyOnWriteForAPI
Enumerate various traits from Windows processes as an aid to threat hunting

Enumerate various traits from Windows processes as an aid to threat hunting

Vulnerability Found on Squid Proxy.

Simple Process Dumper using DMA over a PCIe FPGA device

Penetration testing utility and antivirus assessment tool.

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Visualize the virtual address space of a Windows process on a Hilbert curve.

The swiss army knife of LSASS dumping

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Poc for CVE-2025-7771 to modify PPL Protection

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Exploit for Adobe Reader DC out-of-bounds read vulnerability (CVE-2021-45067) that leaks sensitive information from the sandboxed process via…

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and…