#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Library for unwinding processor call stacks, supporting multiple architectures and operating systems, with build and regression testing instructions.

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

.NET debugger and assembly editor

An advanced memory forensics framework

A frida tool to dump dex in memory to support security engineers analyzing malware.


A forensic evidence collection & analysis toolkit for OS X

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Distributed & real time digital forensics at the speed of the cloud

Dump the memory of a PPL with a userland exploit

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

Easy-to-use live forensics toolbox for Linux endpoints

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Penetration testing utility and antivirus assessment tool.

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

EDRSandblast-GodFault