
moneta
Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

All reasonably stable tools

Dumping processes using the power of kernel space !

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Exploit for Adobe Reader DC out-of-bounds read vulnerability (CVE-2021-45067) that leaks sensitive information from the sandboxed process via…

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

The swiss army knife of LSASS dumping

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A revival of the classic and legendary KsDumper

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Penetration testing utility and antivirus assessment tool.

Visualize the virtual address space of a Windows process on a Hilbert curve.

Enumerate various traits from Windows processes as an aid to threat hunting