
rip_raw
Rip Raw is a small tool to analyse the memory of compromised Linux systems.


This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Poc for CVE-2025-7771 to modify PPL Protection

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Digital forensic acquisition tool for Windows based incident response.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

The swiss army knife of LSASS dumping

A post-exploitation powershell tool for extracting juicy info from memory.

Penetration testing utility and antivirus assessment tool.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Tool that gathers a customizable set of ETW telemetry and generates user-defined detections