Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Memory Forensics

Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.

Kitploit recommended

Top tools

10 selected
volatility3 preview#1

volatility3

GitHubvolatilityfoundation/volatility3
4.3k1 day ago
avml preview#3

avml

GitHubmicrosoft/avml
1.1k22 days ago
velociraptor preview#5

velociraptor

GitHubvelocidex/velociraptor
4.2k14h 39m ago
LiME preview#6

LiME

GitHubjtsylve/lime
2.0k5 months ago
community preview#7

community

GitHubvolatilityfoundation/community
3775 years ago
dwarf2json preview#8

dwarf2json

GitHubvolatilityfoundation/dwarf2json
1581 year ago
dissect preview#9

dissect

GitHubfox-it/dissect
1.1k6 months ago
flare-floss preview#10

flare-floss

GitHubmandiant/flare-floss
4.1k2 days ago
capa preview#11

capa

GitHubmandiant/capa
6.1k2 days ago
yara-x preview#12

yara-x

GitHubvirustotal/yara-x
1.2k13 days ago
NewestRelevanceMost popularRecently updated
624 results
nanodump preview

nanodump

GitHubfortra/nanodump

The swiss army knife of LSASS dumping

privilege-escalationmemory-forensicsexploitation+4
2.1k1 year ago
Collect-MemoryDump preview

Collect-MemoryDump

GitHublethal-forensics/collect-memorydump

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

memory-forensicsforensicsdigital-forensics+1
26510 months ago
ulexecve preview

ulexecve

GitHubanvilsecure/ulexecve

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

memory-forensicsexploitationpost-exploitation+3
2142 years ago
apk-medit preview

apk-medit

GitHubsterrasec/apk-medit

memory search and patch tool on debuggable apk without root & ndk

android-securitymemory-forensicspenetration-testing+2
4313 months ago
Nemesis preview

Nemesis

GitHubzypherion-technologies/nemesis

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

defensive-toolsdynamic-analysis-sandboxingmemory-forensics+2
411 month ago
Blackbone preview

Blackbone

GitHubdarthton/blackbone

Windows memory hacking library

privilege-escalationdynamic-analysis-sandboxingmemory-forensics+9
5.5k4 years ago
RustChain preview

RustChain

GitHubkudaes/rustchain

Hide memory artifacts using ROP and hardware breakpoints.

memory-forensicsexploitationred-teaming+1
1512 years ago
ForensicMiner preview

ForensicMiner

GitHubsecurityjoes/forensicminer

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

disk-forensicsmemory-forensicsforensics+2
1641 year ago
TrickDump preview

TrickDump

GitHubricardojoserf/trickdump

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!

memory-forensicspost-exploitationred-teaming
56624 days ago
YAMA-dev preview

YAMA-dev

GitHubt-tani/yama-dev

Yet Another Memory Analyzer for malware detection

memory-forensicsforensicsmalware-analysis+1
253 years ago
Shelter preview

Shelter

GitHubkudaes/shelter

ROP-based sleep obfuscation to evade memory scanners

exploit-frameworksmemory-forensicsred-teaming
3901 year ago
MultiDump preview

MultiDump

GitHubxre0us/multidump

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

privilege-escalationencryption-decryption-toolsmemory-forensics+4
54110 months ago
NativeDump preview

NativeDump

GitHubricardojoserf/nativedump

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

memory-forensicspost-exploitationred-teaming
74524 days ago
fridump preview

fridump

GitHubnightbringer21/fridump

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

memory-forensicsforensicsinformation-gathering+3
8567 years ago
MemTracer preview

MemTracer

GitHubmayhamad/memtracer

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

memory-forensicsforensicsmalware-analysis+1
644 years ago
Linpmem preview

Linpmem

GitHubvelocidex/linpmem

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

memory-forensicsforensicsdigital-forensics+1
1051 year ago
PPLBlade preview

PPLBlade

GitHubtastypepperoni/pplblade

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

privilege-escalationmemory-forensicsexploitation+2
5973 years ago
ModuleShifting preview

ModuleShifting

GitHubnaksyn/moduleshifting

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

memory-forensicsred-teamingpayload-development+1
1352 years ago
Previous1…313233…35Next