
BareMetal-RAM-Dumper
A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.


An advanced memory forensics framework

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Penetration testing utility and antivirus assessment tool.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Utility to find AES keys in running processes

RAM imaging utility.
