Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Memory Forensics

Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.

Kitploit recommended

Top tools

10 selected
volatility3 preview#1

volatility3

GitHub
volatilityfoundation/volatility3
4.3k12h 9m ago
avml preview#3

avml

GitHubmicrosoft/avml
1.1k21 days ago
velociraptor preview#5

velociraptor

GitHubvelocidex/velociraptor
4.2k20h 32m ago
LiME preview#6

LiME

GitHubjtsylve/lime
2.0k5 months ago
community preview#7

community

GitHubvolatilityfoundation/community
3775 years ago
dwarf2json preview#8

dwarf2json

GitHubvolatilityfoundation/dwarf2json
1581 year ago
dissect preview#9

dissect

GitHubfox-it/dissect
1.1k6 months ago
flare-floss preview#10

flare-floss

GitHubmandiant/flare-floss
4.1k1 day ago
capa preview#11

capa

GitHubmandiant/capa
6.1k22h 42m ago
yara-x preview#12

yara-x

GitHubvirustotal/yara-x
1.2k12 days ago
NewestRelevanceMost popularRecently updated
621 results
wmi-static-spoofer preview

wmi-static-spoofer

GitHubalex3434/wmi-static-spoofer

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

privilege-escalationmemory-forensicspersistence-mechanisms+4
5087 years ago
mal_unpack preview

mal_unpack

GitHubhasherezade/mal_unpack

Dynamic unpacker based on PE-sieve

dynamic-analysis-sandboxingmemory-forensicsreverse-engineering+2
8274 months ago
mXtract preview

mXtract

GitHubrek7/mxtract

mXtract - Memory Extractor & Analyzer

password-crackingmemory-forensicsforensics+2
5874 years ago
DumpBrowserSecrets preview

DumpBrowserSecrets

GitHubmaldev-academy/dumpbrowsersecrets

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

password-crackingencryption-decryption-toolsmemory-forensics+8
7983 months ago
community preview

community

GitHubvolatilityfoundation/community

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

memory-forensicsmalware-analysisdigital-forensics
3775 years ago
DeepSleep preview

DeepSleep

GitHubtheflink/deepsleep

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

memory-forensicsexploitationred-teaming+1
3764 years ago
Pixel_GPU_Exploit preview

Pixel_GPU_Exploit

GitHub0x36/pixel_gpu_exploit

Android 14 kernel exploit for Pixel7/8 Pro

android-securityprivilege-escalationmemory-forensics+4
5572 years ago
Incident-Response-Powershell preview

Incident-Response-Powershell

GitHubbert-janp/incident-response-powershell

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

disk-forensicsioc-managementmemory-forensics+6
8073 months ago
BeaconEye preview

BeaconEye

GitHubccob/beaconeye

Hunts out CobaltStrike beacons and logs operator command output

memory-forensicsmalware-analysisdigital-forensics+2
9642 years ago
MalConfScan preview

MalConfScan

GitHubjpcertcc/malconfscan

Volatility plugin for extracts configuration data of known malware

memory-forensicsvulnerability-analysisforensics+3
4992 years ago
keepass-password-dumper preview

keepass-password-dumper

GitHubvdohney/keepass-password-dumper

Original PoC for CVE-2023-32784

memory-forensicspassword-attacksvulnerability-analysis+3
6513 years ago
ir-rescue preview

ir-rescue

GitHubdiogo-fernan/ir-rescue

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

disk-forensicsmemory-forensicsnetwork-forensics+6
4895 years ago
extractTVpasswords preview

extractTVpasswords

GitHubvah13/extracttvpasswords

tool to extract passwords from TeamViewer memory using Frida

password-crackingmemory-forensicsexploitation+3
4638 years ago
CobaltStrikeScan preview

CobaltStrikeScan

GitHubapr4h/cobaltstrikescan

Scan files or process memory for CobaltStrike beacons and parse their configuration

defensive-toolsioc-managementmemory-forensics+4
9195 years ago
irflow-timeline preview

irflow-timeline

GitHubr3nzsec/irflow-timeline

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

disk-forensicsioc-managementmemory-forensics+7
3041 day ago
Hunt-Sleeping-Beacons preview

Hunt-Sleeping-Beacons

GitHubtheflink/hunt-sleeping-beacons

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

defensive-toolsmemory-forensicsforensics+3
6787 months ago
ghost preview

ghost

GitHubpandaadir05/ghost

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

defensive-toolsmemory-forensicsreverse-engineering+6
3821 month ago
SwishDbgExt preview

SwishDbgExt

GitHubmagnetforensics/swishdbgext

Incident Response & Digital Forensics Debugging Extension

memory-forensicsreverse-engineeringdebuggers+3
4017 years ago
Previous1…567…35Next