#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.


A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Linux Evidence Acquisition Framework

Incident Response & Digital Forensics Debugging Extension

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)

Defund the Police.

Dumping processes using the power of kernel space !

SALT - SLUB ALlocator Tracer for the Linux kernel

CVE-2024-27398 POC