#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Mimikatz implementation in pure Python

volatility explorer (volatility 2)

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Utility to find AES keys in running processes

Incident Response & Digital Forensics Debugging Extension

Scan files or process memory for CobaltStrike beacons and parse their configuration


Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Volatility Explorer Suit (volatility 3)

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…


A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

GUI for Volatility forensics tool written in PyQT5
