
cormem-read-poc
This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Poc for CVE-2025-7771 to modify PPL Protection

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Virtual Machine Introspection, Tracing & Debugging

Tool to make in memory man in the middle

Penetration testing utility and antivirus assessment tool.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

The swiss army knife of LSASS dumping

A python script developed to process Windows memory images based on triage type.

Enumerate various traits from Windows processes as an aid to threat hunting

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

A canary designed to minimize the impact from certain Ransomware actors

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .