#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

All reasonably stable tools

Windows tool for dumping malware PE files from memory back to disk for analysis.

Utility to find AES keys in running processes

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

A PowerShell Module Dedicated to Reverse Engineering

An Active Defense and EDR software to empower Blue Teams

Some of my publicly available Malware analysis and Reverse engineering.

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Dump cookies and credentials directly from Chrome/Edge process memory

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

A memory-based evasion technique which makes shellcode invisible from process start to end.

jemalloc heap exploitation framework

Hunts out CobaltStrike beacons and logs operator command output