{"adoption": {"forks": 1014, "observed_at": "2026-08-28T04:10:08.988531+00:00", "stars": 7899}, "canonical_url": "https://ross.abutalabs.com/products/pcileech", "card": {"archived": false, "artifact_type": "application", "description": "Direct Memory Access (DMA) Attack Software", "domain": ["security", "penetration-testing", "reverse-engineering", "hardware", "operating-systems"], "enriched": true, "function": ["security", "penetration-testing", "reverse-engineering", "developer-tools", "cli"], "health_score": 88, "homepage": null, "language": "C", "license": "AGPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["ufrisk/pcileech", "ufrisk/pcileech-fpga"], "name": "PCILeech", "platform": ["windows", "cli", "cpp"], "pushed_at": "2026-07-25T20:12:35+00:00", "repo": "ufrisk/pcileech", "stars": 7899, "tags": ["dma-attack", "pcie", "memory-acquisition", "fpga", "kernel-implants", "forensics", "red-team", "linux"], "topics": [], "urls": [], "use_cases": ["read target system memory over PCIe DMA without drivers", "dump live RAM from a Windows or Linux machine", "insert kernel implants to access the file system as a mounted drive", "bypass Windows logon password requirement", "acquire memory from remote systems via DumpIt or WinPmem", "analyze memory dump files for forensics", "perform red team physical access attacks with FPGA hardware"], "what_it_is": "PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system memory without requiring drivers on the target. It can insert kernel implants, access live RAM and file systems, remove logon password requirements, and spawn system shells on x64 UEFI, Linux, FreeBSD, and Windows targets.", "when_to_avoid": ["you need a non-invasive or purely network-based security scanner", "you lack physical access or compatible PCIe hardware and no software acquisition method applies", "you're looking for a defensive-only monitoring tool", "your target systems are 32-bit or unsupported architectures"], "when_to_choose": ["you need driverless memory access to a target via PCIe hardware", "you're doing security research, forensics, or red team physical attacks", "you want to acquire live memory from Windows, Linux, FreeBSD, or UEFI x64 systems", "you need kernel-level access to a machine you have physical access to"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/repos/ufrisk/pcileech", "repo": "ufrisk/pcileech", "role": "main", "score": 65}, {"path": "/repos/ufrisk/pcileech-fpga", "repo": "ufrisk/pcileech-fpga", "role": "infra", "score": 57}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:10:08.988531+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T17:33:25.993921+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8f1d3437f467c62ce0d6cb8f78ab69825a5c5fc80bab6d39ee27b89022daaf3", "fetched_at": "2026-08-28T04:10:08.988531+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ufrisk/pcileech"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 94, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3689, "days_push": 39, "days_rel": 594, "gap_med": null, "n_releases_24m": 1}, "score": 65, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}