#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

A generic game/software hacking tool written from the ground up in Rust.
Code Injection, Inject malicious payload via pagetables pml4.

Windows tool for dumping malware PE files from memory back to disk for analysis.

Hunts out CobaltStrike beacons and logs operator command output

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Java Agent memory horse scanner combined with Call Graph modus

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

An automatic unpacker and logger for DotNet Framework targeting files

Cobalt Strike UDRL for memory scanner evasion.

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.