
fridump
Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Proof-of-concept exploit for Linux kernel FUSE information leak (CVE-2024-44947), demonstrating beyond-EOF memory disclosure via mmap and including…

Technical analysis of CVE-2020-1206 (SMBleed) kernel information disclosure vulnerability in Windows SMBv3, including unauthenticated memory leak…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Defund the Police.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…


A post-exploitation powershell tool for extracting juicy info from memory.

This is the development tree. Production downloads are at:

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…


Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

mXtract - Memory Extractor & Analyzer

Incident Response Forensic Framework

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Collecting & Hunting for IOCs with gusto and style