
DMA-ProcessDumper
Simple Process Dumper using DMA over a PCIe FPGA device

Simple Process Dumper using DMA over a PCIe FPGA device

Rebuild of Windows kernel driver functions KeAttachProcess and KeDetachProcess, used for process attachment and anti-cheat bypass research.

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

A revival of the classic and legendary KsDumper

Protect process by shellcode

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

PoCs and tools for investigation of Windows process execution techniques

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

x64 Dynamic Reverse Engineering Toolkit

Exploit for a LogMeIn/GoTo Windows kernel driver race condition that duplicates SYSTEM handles, enabling thread-token impersonation and local…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A lightweight dynamic instrumentation library

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

An API hooking framework for intercepting and monitoring Windows applications