
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Volatility 3 ported to Rust. Same output, much faster.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Hunts out CobaltStrike beacons and logs operator command output

volatility explorer (volatility 2)

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Security sensor for realtime threat detection and protection


Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Volatility plugin for extracts configuration data of known malware

Differential Analysis of Malware in Memory

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.