
dumpscan
Finding secrets in kernel and user memory

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A canary designed to minimize the impact from certain Ransomware actors

A BOF designed to inspect processes memory and addresses

Proof-of-concept exploit for ImageMagick CVE-2017-15277 memory leak vulnerability, designed for use with the gifoeb fuzzing framework.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…


Collection of forensic tools

DLL Injection tool to unlock guest VMs

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

Offset Independent Credential Extraction Tool

Heap analysis tooling for dlmalloc