#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Dynamic unpacker based on PE-sieve

mXtract - Memory Extractor & Analyzer

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Android 14 kernel exploit for Pixel7/8 Pro

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Hunts out CobaltStrike beacons and logs operator command output

Volatility plugin for extracts configuration data of known malware

Original PoC for CVE-2023-32784

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

tool to extract passwords from TeamViewer memory using Frida

Scan files or process memory for CobaltStrike beacons and parse their configuration

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Incident Response & Digital Forensics Debugging Extension