
SuperMem
A python script developed to process Windows memory images based on triage type.

A python script developed to process Windows memory images based on triage type.

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

GDB-based Python script for analyzing dlmalloc heap structures, providing chunk inspection, mstate enumeration, and offline snapshot analysis for…

GDB Python script for analyzing the talloc memory allocator, enabling heap chunk inspection, validation, pool analysis, and tree walking for…

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Carves BitLocker Volume Master Keys (VMKs) from memory dumps, disk images, and unallocated space for forensic decryption of encrypted volumes.

Exploit script for CVE-2025-14847 (MongoBleed) that triggers heap memory disclosure in MongoDB by sending crafted OP_MSG packets, leaking sensitive…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Extracts SSH private keys from ssh-agent memory by exploiting a bug, using root-level memory dumps and ASN.1 parsing for key recovery.

Retrieve the master password of a keepass database <= 2.53.1