- London, UK
- https://www.twitter.com/emd3l
Stars
ksfinder - Retrieve exported kernel symbols from physical memory dumps
📚 Freely available programming books
A core plugin for radare2 to integrate with FIRST server
Recover 64 bit ELF executables from memory dump
Code for the DIMVA 2018 paper: "MemScrimper: Time- and Space-Efficient Storage of Malware Sandbox Memory Dumps"
Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.
python library to examine ptmalloc (the glibc userland heap implementation)
Devestating and awesome Linux X86_64 ELF Virus
ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.
inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps …
Abstract Binary Format Manipulation - ELF, PE and Mach-O format
An advanced memory forensics framework
Memory forensics of virtualization environments
Binary analysis and management framework