#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Free hands-on digital forensics labs for students and faculty
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…


A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

A powerful and user-friendly binary analysis platform!

Ghidra is a software reverse engineering (SRE) framework

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation

Malware Configuration And Payload Extraction

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

UNIX-like reverse engineering framework and command-line toolset

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.