#1Tools for analyzing RAM dumps to find running processes, network connections, and hidden malware.
Kitploit recommended

Linux kernel use-after-free (UAF) privilege escalation exploit for CVE-2018-17182, providing root shell access on affected kernels (3.16 to 4.18.8).…

An automatic unpacker and logger for DotNet Framework targeting files

Code Injection, Inject malicious payload via pagetables pml4.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

CVE-2026-43499 PoC

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Digital forensic acquisition tool for Windows based incident response.

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

SALT - SLUB ALlocator Tracer for the Linux kernel

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Memoro: A Detailed Heap Profiler

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Intel 64/Windows low-level experiments

iOS 14 kernel exploit for CVE-2021-30807 targeting IOMobileFramebuffer, with tunable memory allocation for jailbreak development on A11+ devices.

Using CVE-2023-21768 to manual map kernel mode driver

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.