
PyMemoryEditor
A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

A lightweight dynamic instrumentation library

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

An API hooking framework for intercepting and monitoring Windows applications

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

PoCs and tools for investigation of Windows process execution techniques

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

A revival of the classic and legendary KsDumper

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Exploit for a LogMeIn/GoTo Windows kernel driver race condition that duplicates SYSTEM handles, enabling thread-token impersonation and local…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…