
ATMMalScan
Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

A frida tool to dump dex in memory to support security engineers analyzing malware.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Mimikatz implementation in pure Python

OS X Auditor is a free Mac OS X computer forensics tool

A Linux version of the ProcDump Sysinternals tool

Software sandbox for storage of sensitive information in memory.

Memory Debugger for Windows, Linux, Mac, and Android

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

The swiss army knife of LSASS dumping

A post-exploitation powershell tool for extracting juicy info from memory.

Windows tool for dumping malware PE files from memory back to disk for analysis.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

All reasonably stable tools