#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Ghidra is a software reverse engineering (SRE) framework
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

UNIX-like reverse engineering framework and command-line toolset

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Defund the Police.

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

A powerful and user-friendly binary analysis platform!

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Cheat Engine. A development environment focused on modding

Malware Configuration And Payload Extraction

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Windows memory hacking library

Free hands-on digital forensics labs for students and faculty

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…