Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Memory Forensics

Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.

Kitploit recommended

Top tools

10 selected
volatility3 preview#1

volatility3

GitHubvolatilityfoundation/volatility3
4.3k1 day ago
avml preview#3

avml

GitHubmicrosoft/avml
1.1k22 days ago
velociraptor preview#5

velociraptor

GitHubvelocidex/velociraptor
4.2k15h 57m ago
LiME preview#6

LiME

GitHubjtsylve/lime
2.0k5 months ago
community preview#7

community

GitHubvolatilityfoundation/community
3775 years ago
dwarf2json preview#8

dwarf2json

GitHubvolatilityfoundation/dwarf2json
1581 year ago
dissect preview#9

dissect

GitHubfox-it/dissect
1.1k6 months ago
flare-floss preview#10

flare-floss

GitHubmandiant/flare-floss
4.1k2 days ago
capa preview#11

capa

GitHubmandiant/capa
6.1k2 days ago
yara-x preview#12

yara-x

GitHubvirustotal/yara-x
1.2k13 days ago
NewestRelevanceMost popularRecently updated
624 results
Squalr preview

Squalr

GitHubsqualr/squalr

A generic game/software hacking tool written from the ground up in Rust.

dynamic-analysis-sandboxingmemory-forensicsexploitation+5
1512 months ago
PageTableInjection preview

PageTableInjection

GitHubkkent030315/pagetableinjection

Code Injection, Inject malicious payload via pagetables pml4.

memory-forensicsexploitationbinary-exploitation
2445 years ago
Process-Dump preview

Process-Dump

GitHubglmcdona/process-dump

Windows tool for dumping malware PE files from memory back to disk for analysis.

memory-forensicsreverse-engineeringforensics+2
1.9k3 years ago
BeaconEye preview

BeaconEye

GitHubccob/beaconeye

Hunts out CobaltStrike beacons and logs operator command output

memory-forensicsmalware-analysisdigital-forensics+2
9642 years ago
HandleKatz preview

HandleKatz

GitHubcodewhitesec/handlekatz

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

defensive-toolsmemory-forensicspayload-generation+3
5983 years ago
DeepSleep preview

DeepSleep

GitHubtheflink/deepsleep

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

memory-forensicsexploitationred-teaming+1
3764 years ago
Hunt-Sleeping-Beacons preview

Hunt-Sleeping-Beacons

GitHubtheflink/hunt-sleeping-beacons

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

defensive-toolsmemory-forensicsforensics+3
6787 months ago
CrossC2Kit preview

CrossC2Kit

GitHubcrossc2/crossc2kit

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

penetration-testing-frameworksprivilege-escalationexploit-frameworks+7
2293 years ago
dismember preview

dismember

GitHubliamg/dismember

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

memory-forensicsforensicsinformation-gathering+2
6744 years ago
MemoryShellHunter preview

MemoryShellHunter

GitHubsf197/memoryshellhunter

Java Agent memory horse scanner combined with Call Graph modus

dynamic-analysis-sandboxingmemory-forensicsweb-security+1
653 years ago
systeminformer preview

systeminformer

GitHubwinsiderss/systeminformer

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

general-purpose-utilitiesmemory-forensicsnetwork-mapping+6
15.6k18h 48m ago
DotDumper preview

DotDumper

GitHubadvanced-threat-research/dotdumper

An automatic unpacker and logger for DotNet Framework targeting files

dynamic-analysis-sandboxingmemory-forensicsreverse-engineering+4
2663 years ago
AceLdr preview

AceLdr

GitHubkyleavery/aceldr

Cobalt Strike UDRL for memory scanner evasion.

exploit-frameworksmemory-forensicspost-exploitation+2
1.0k2 years ago
WhacAMole preview

WhacAMole

GitHubignacioj/whacamole

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

ioc-managementdynamic-analysis-sandboxingmemory-forensics+9
451 year ago
aftermath preview

aftermath

GitHubjamf/aftermath

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

memory-forensicsforensicsdigital-forensics+3
59411 months ago
TiEtwAgent preview

TiEtwAgent

GitHubxuanxuan0/tietwagent

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

defensive-toolsmemory-forensicsmalware-analysis+1
3005 years ago
ipa-medit preview

ipa-medit

GitHubsterrasec/ipa-medit

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

ios-securitymemory-forensicsmobile-app-pentesting+3
2071 year ago
CyberPipe preview

CyberPipe

GitHubdwmetz/cyberpipe

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

disk-forensicsmemory-forensicsforensics+2
3439 months ago
Previous1…303132…35Next