#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

Dump TeamViewer ID and password from memory. Works much better than other tools.

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

POC for CVE-2018-0824

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Panic button for protection against cold boot attacks

A Windows kernel dump C++ parser library with Python 3 bindings.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

Volatility 3 ported to Rust. Same output, much faster.

Learning Linux Binary Analysis, published by Packt

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

volatility explorer (volatility 2)

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Process heap analysis framework - Windows/Linux - record type inference and forensics