Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Memory Forensics

Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.

Kitploit recommended

Top tools

10 selected
volatility3 preview#1

volatility3

GitHubvolatilityfoundation/volatility3
4.3k1 day ago
avml preview#3

avml

GitHubmicrosoft/avml
1.1k21 days ago
velociraptor preview#5

velociraptor

GitHubvelocidex/velociraptor
4.2k6h 36m ago
LiME preview#6

LiME

GitHubjtsylve/lime
2.0k5 months ago
community preview#7

community

GitHubvolatilityfoundation/community
3775 years ago
dwarf2json preview#8

dwarf2json

GitHubvolatilityfoundation/dwarf2json
1581 year ago
dissect preview#9

dissect

GitHubfox-it/dissect
1.1k6 months ago
flare-floss preview#10

flare-floss

GitHubmandiant/flare-floss
4.1k1 day ago
capa preview#11

capa

GitHubmandiant/capa
6.1k1 day ago
yara-x preview#12

yara-x

GitHubvirustotal/yara-x
1.2k13 days ago
NewestRelevanceMost popularRecently updated
621 results
cve-2019-2215 preview

cve-2019-2215

GitHubkangtastic/cve-2019-2215

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

android-securityprivilege-escalationmemory-forensics+4
1346 years ago
LsassReflectDumping preview

LsassReflectDumping

GitHuboffensive-panda/lsassreflectdumping

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

memory-forensicspassword-attackspost-exploitation+1
2201 year ago
ulexecve preview

ulexecve

GitHubanvilsecure/ulexecve

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

memory-forensicsexploitationpost-exploitation+3
2142 years ago
teamviewer-dumper preview

teamviewer-dumper

GitHubattackercan/teamviewer-dumper

Dump TeamViewer ID and password from memory. Works much better than other tools.

password-crackingreconnaissancememory-forensics+3
988 years ago
CVE-2023-28252 preview

CVE-2023-28252

GitHubfortra/cve-2023-28252

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

privilege-escalationmemory-forensicsvulnerability-analysis+4
1843 years ago
UnmarshalPwn preview

UnmarshalPwn

GitHubcodewhitesec/unmarshalpwn

POC for CVE-2018-0824

memory-forensicsvulnerability-analysiscode-analysis+2
873 years ago
ModuleShifting preview

ModuleShifting

GitHubnaksyn/moduleshifting

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

memory-forensicsred-teamingpayload-development+1
1352 years ago
Centry preview

Centry

GitHub0xpoly/centry

Panic button for protection against cold boot attacks

defensive-toolsencryption-decryption-toolsmemory-forensics+3
1454 years ago
kdmp-parser preview

kdmp-parser

GitHub0vercl0k/kdmp-parser

A Windows kernel dump C++ parser library with Python 3 bindings.

memory-forensicsforensicsdigital-forensics+1
21111 months ago
clairvoyance preview

clairvoyance

GitHub0vercl0k/clairvoyance

Visualize the virtual address space of a Windows process on a Hilbert curve.

memory-forensicsforensicsdigital-forensics
3085 years ago
RogueAssemblyHunter preview

RogueAssemblyHunter

GitHubbohops/rogueassemblyhunter

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

defensive-toolsmemory-forensicsforensics+2
1204 years ago
vol-rs preview

vol-rs

GitHubdaffainfo/vol-rs

Volatility 3 ported to Rust. Same output, much faster.

memory-forensicsvulnerability-analysisforensics+3
17111 days ago
Learning-Linux-Binary-Analysis preview

Learning-Linux-Binary-Analysis

GitHubpacktpublishing/learning-linux-binary-analysis

Learning Linux Binary Analysis, published by Packt

memory-forensicsexploitationreverse-engineering+7
893 years ago
IRTriage preview

IRTriage

GitHubajmartel/irtriage

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

memory-forensicsforensicsdigital-forensics+1
13910 years ago
TuxResponse preview

TuxResponse

GitHubla3ar0v/tuxresponse

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

disk-forensicsmemory-forensicsscripting-automation+5
904 months ago
VolExp preview

VolExp

GitHubmemoryforensics1/volexp

volatility explorer (volatility 2)

memory-forensicsforensicsmalware-analysis+2
955 years ago
dwarf2json preview

dwarf2json

GitHubvolatilityfoundation/dwarf2json

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

memory-forensicsreverse-engineeringdigital-forensics+2
1581 year ago
python-haystack preview

python-haystack

GitHubtrolldbois/python-haystack

Process heap analysis framework - Windows/Linux - record type inference and forensics

memory-forensicsreverse-engineeringforensics+2
959 years ago
Previous1…101112…35Next