Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Memory Forensics

Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.

Kitploit recommended

Top tools

10 selected
volatility3 preview#1

volatility3

GitHubvolatilityfoundation/volatility3
4.3k14h 52m ago
avml preview#3

avml

GitHubmicrosoft/avml
1.1k20 days ago
velociraptor preview#5

velociraptor

GitHubvelocidex/velociraptor
4.2k14h 8m ago
LiME preview#6

LiME

GitHubjtsylve/lime
2.0k5 months ago
community preview#7

community

GitHubvolatilityfoundation/community
3775 years ago
dwarf2json preview#8

dwarf2json

GitHubvolatilityfoundation/dwarf2json
1581 year ago
dissect preview#9

dissect

GitHubfox-it/dissect
1.1k6 months ago
flare-floss preview#10

flare-floss

GitHubmandiant/flare-floss
4.1k18h 9m ago
capa preview#11

capa

GitHubmandiant/capa
6.1k16h 17m ago
yara-x preview#12

yara-x

GitHubvirustotal/yara-x
1.2k12 days ago
NewestRelevanceMost popularRecently updated
621 results
CVE-2021-46702 preview

CVE-2021-46702

GitHubexmak-s/cve-2021-46702

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

memory-forensicsexploitationinformation-gathering+2
64 years ago
community preview

community

GitHubvolatilityfoundation/community

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

memory-forensicsmalware-analysisdigital-forensics
3775 years ago
dwarf2json preview

dwarf2json

GitHubvolatilityfoundation/dwarf2json

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

memory-forensicsreverse-engineeringdigital-forensics+2
1581 year ago
LiME preview

LiME

GitHubjtsylve/lime

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

memory-forensicsforensicsmobile-forensics+2
2.0k5 months ago
libpeconv preview

libpeconv

GitHubhasherezade/libpeconv

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

memory-forensicsreverse-engineeringshellcode+4
1.4k4 months ago
awesome-incident-response preview

awesome-incident-response

GitHubmeirwah/awesome-incident-response

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

disk-forensicsmemory-forensicsforensics+9
9.4k1 month ago
timesketch preview

timesketch

GitHubgoogle/timesketch

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

disk-forensicsioc-managementmemory-forensics+7
3.4k1 day ago
avml preview

avml

GitHubmicrosoft/avml

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

memory-forensicsforensicsdigital-forensics+1
1.1k20 days ago
memory-forensic preview

memory-forensic

GitHubsecurityronin/memory-forensic

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

ioc-managementmemory-forensicsnetwork-forensics+7
1020 days ago
Sandb0x-Xtract0r preview

Sandb0x-Xtract0r

GitHubdarnellwashingtonjr94-art/sandb0x-xtract0r

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

dynamic-analysis-sandboxingmemory-forensicsnetwork-forensics+3
33 days ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

privilege-escalationmemory-forensicspersistence-mechanisms+6
521 days ago
memdumper preview

memdumper

GitHubcenobyte-vincit/memdumper

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

memory-forensicsids-ips-evasioninformation-gathering+4
122 days ago
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis preview

RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis

GitHubkaandemir993/redline-stealer-c2-defender-bypass-payload-analysis

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

memory-forensicspersistence-mechanismsreverse-engineering+4
126 days ago
keepass-exfil-forensics preview

keepass-exfil-forensics

GitHubpugazhendii22/keepass-exfil-forensics

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

packet-sniffing-analysispassword-crackingmemory-forensics+6
26 days ago
mal_unpack preview

mal_unpack

GitHubhasherezade/mal_unpack

Dynamic unpacker based on PE-sieve

dynamic-analysis-sandboxingmemory-forensicsreverse-engineering+2
8274 months ago
GarbageMan preview

GarbageMan

GitHubwithsecurelabs/garbageman

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

memory-forensicsreverse-engineeringdata-exfiltration+3
1213 years ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

privilege-escalationvulnerability-scannersmemory-forensics+6
11 month ago
physmem2profit preview

physmem2profit

GitHubreverseclabs/physmem2profit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

memory-forensicspassword-attacksdata-exfiltration+4
4224 years ago
Previous123…35Next