#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Volatility Explorer Suit (volatility 3)

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

PoC and technical details of CVE-2025-24204

An interactive memory info for pwning / exploiting

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Use YARA rules on Time Travel Debugging traces


A canary designed to minimize the impact from certain Ransomware actors

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Spectre exploit

OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

Small toolkit for extracting information and dumping sensitive strings from Windows processes

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

CVE-2026-50416: Windows 11 KASLR bypass

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

A host based IDS written in C# Targetted at Metasploit