Ross ROSS = Recommend OSS · open-source software intelligence for agents

PCILeech

Direct Memory Access (DMA) Attack Software observed · 2026-08-28

github.com/ufrisk/pcileech · C · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

65/100

  • Activity 94
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3689
  • days_rel: 594
  • days_push: 39
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

7899 stars · 1014 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system memory without requiring drivers on the target. It can insert kernel implants, access live RAM and file systems, remove logon password requirements, and spawn system shells on x64 UEFI, Linux, FreeBSD, and Windows targets.

Use cases

  • read target system memory over PCIe DMA without drivers
  • dump live RAM from a Windows or Linux machine
  • insert kernel implants to access the file system as a mounted drive
  • bypass Windows logon password requirement
  • acquire memory from remote systems via DumpIt or WinPmem
  • analyze memory dump files for forensics
  • perform red team physical access attacks with FPGA hardware

When to choose

  • you need driverless memory access to a target via PCIe hardware
  • you're doing security research, forensics, or red team physical attacks
  • you want to acquire live memory from Windows, Linux, FreeBSD, or UEFI x64 systems
  • you need kernel-level access to a machine you have physical access to

When to avoid

  • you need a non-invasive or purely network-based security scanner
  • you lack physical access or compatible PCIe hardware and no software acquisition method applies
  • you're looking for a defensive-only monitoring tool
  • your target systems are 32-bit or unsupported architectures

Facets

application · maturity active

security penetration-testing reverse-engineering developer-tools cli security penetration-testing reverse-engineering hardware operating-systems windows cli cpp dma-attack pcie memory-acquisition fpga kernel-implants forensics red-team linux

1 source

Member repositories

RepositoryRoleHealth v2
ufrisk/pcileechmain65
ufrisk/pcileech-fpgainfra57

For agents

markdown · JSON · MCP: product_card(name="ufrisk/pcileech")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem