#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…
Direct Memory Access (DMA) Attack Software

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

List of Awesome CobaltStrike Resources

You didn't think I'd go and leave the blue team out, right?

A Linux version of the ProcDump Sysinternals tool

Security sensor for realtime threat detection and protection

OS X Auditor is a free Mac OS X computer forensics tool

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.