
volatility
An advanced memory forensics framework

An advanced memory forensics framework

convert ELF/DWARF symbol and type information into vol3's intermediate JSON


Penetration testing utility and antivirus assessment tool.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.


RAM imaging utility.

Utility to find AES keys in running processes

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.