#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…
Linux Memory Cryptographic Keys Extractor

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

🐍 High-performance, multi-threaded YARA & IOC scanner

A curated collection of DFIR skills and workflows for InfoSec practitioners.

ROP-based sleep obfuscation to evade memory scanners

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

A low pin count sniffer for ICEStick - targeting TPM chips

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

A little tool to play with the Seclogon service

helps visualize heap operations for pwn and debugging

Collecting & Hunting for IOCs with gusto and style

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Automagically extract forensic timeline from volatile memory dump

A python script developed to process Windows memory images based on triage type.

Main repository to pull all NCC Group Cisco ASA-related tool projects.