#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

A centralized and enhanced memory analysis platform

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Linux Evidence Acquisition Framework

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Script for automating Linux memory capture and analysis

Malware Configuration And Payload Extraction

helps visualize heap operations for pwn and debugging

Automagically extract forensic timeline from volatile memory dump

Free hands-on digital forensics labs for students and faculty

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

The multi-platform memory acquisition tool.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…