
memhunter
Live hunting of code injection techniques

Live hunting of code injection techniques

Code Injection, Inject malicious payload via pagetables pml4.

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

PoC code for CVE-2017-13253

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and…

PrISM: A Scalable Probabilistic RowHammer Mitigation (ISCA 2026). Ramulator2 source code and evaluation scripts.

A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.


Meltdown Exploit PoC

Proof of concept & details for CVE-2025-21298

Learning Linux Binary Analysis, published by Packt

Use-After-Free in Netfilter nf_tables when processing batch requests CVE-2023-32233