
aes-finder
Utility to find AES keys in running processes

Utility to find AES keys in running processes

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in…

RAM imaging utility.

Penetration testing utility and antivirus assessment tool.

convert ELF/DWARF symbol and type information into vol3's intermediate JSON



An advanced memory forensics framework