#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and…

Extract Windows credentials directly from VM memory snapshots and virtual disks

A centralized and enhanced memory analysis platform

Collection of forensic tools

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Live hunting of code injection techniques


Dumping processes using the power of kernel space !

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

The multi-platform memory acquisition tool.

Open source memory scanner written in C++

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Cobalt Strike UDRL for memory scanner evasion.