#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Seer - a gui frontend to gdb

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Mimikatz implementation in pure Python

Meltdown Exploit PoC

This is the development tree. Production downloads are at:

A post-exploitation powershell tool for extracting juicy info from memory.

Memory Debugger for Windows, Linux, Mac, and Android

The swiss army knife of LSASS dumping

Hybrid kernel combining Mach, FreeBSD, and IOKit for macOS and iOS. Provides core OS services, driver framework, and security policy enforcement on…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.


Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Software sandbox for storage of sensitive information in memory.

More than a ReClass port to the .NET platform.

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…