
memdumper
滥用 macOS 调试器授权和 DYLD_INSERT_LIBRARIES 来转储或搜索正在运行进程的内存,同时将 EDR 归因转移到已签名的辅助二进制文件。

针对 RedLine Stealer 的逆向工程分析,这是一个基于 .NET 的信息窃取程序,使用 C2 域名(198.46.86.63、tempuri.org),绕过 Windows Defender,并提取 7200 KB 的载荷。

适用于 TryHackMe DFIR 挑战的网络取证 Writeup 及配套工具:从 PCAP 流量中逆向还原 hex→Base64→XOR 数据外泄链,然后利用 CVE-2023-32784 从进程内存转储中恢复 KeePass 主密码。

在受控环境中运行加壳恶意软件,等待其自行解包,从内存中转储 PE 文件和 shellcode,并终止该进程。

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

一个 Jupyter notebook,用于协助分析 Volatility 内存提取框架生成的输出。

攻击性令牌收集实用工具,可搜索 x64 进程内存和 TokenBroker 缓存文件,在 Office、Edge、Teams 和 PowerShell 中查找 Azure AD/O365 JWT 令牌。

List of Awesome CobaltStrike Resources

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

枚举 Windows 定时器队列计时器,以检测 Ekko 睡眠混淆,辅助内存取证和恶意软件分析,识别规避检测的内存驻留威胁。

一个基于分类类型处理 Windows 内存镜像的 Python 脚本。

示例演示了基于 Go 的可信执行环境,在 ARM TrustZone 和 RISC-V 上,将并发运行的 unikernels 分别用作 Trusted OS、Trusted Applet 和 Main OS。

一个带有 Python 3 绑定的 Windows 内核转储 C++ 解析器库。

Toy scripts for playing with WinDbg JS API

Golang bindings for PE-sieve

在时间旅行调试跟踪中使用 YARA 规则