
python-haystack
Process heap analysis framework - Windows/Linux - record type inference and forensics

Process heap analysis framework - Windows/Linux - record type inference and forensics

Dumping processes using the power of kernel space !

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

PoCs and tools for investigation of Windows process execution techniques

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

A happy heap editor to support your exploitation process :slightly_smiling_face:

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

An event driven multi-core process debugging, tracing, and manipulation framework.

Automates repair of malformed UPX headers in ELF binaries, restoring magic, filesize, blocksize, and overlay fields so standard unpackers can process…

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…