#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…
GPG Reaper - Obtain/Steal/Restore GPG Private Keys from gpg-agent cache/memory

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Report and exploit of CVE-2023-36427

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

CVE-2025-31200 - @Noahhw46 figured it out

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

This is POC for IOS 0click CVE-2025-43300

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

Exploit tool leveraging CVE-2020-12928 (AMD RyzenMaster driver) for game memory manipulation and anti-cheat bypass on Windows 10 with AMD Ryzen CPUs.

Tools for the Computer Incident Response Team :computer:

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

Tool for CVE-2018-16323

Offline AI Security Assistant for Air-Gapped Pentesting

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…