
CrossC2Kit
CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Incident Response Forensic Framework


Presented at Recon Montreal 2018

Defund the Police.


A post-exploitation powershell tool for extracting juicy info from memory.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

mXtract - Memory Extractor & Analyzer

Collecting & Hunting for IOCs with gusto and style

Dump TeamViewer ID and password from memory. Works much better than other tools.

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

CVE-2026-50416: Windows 11 KASLR bypass

Volatility plugin to extract X screenshots from a memory dump

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.


Documents the VectorFreed librsvg use-after-free RCE chain (CVE-2026-96889) with an SVG generator PoC and remediation guidance for librsvg, Next.js,…