
MultiDump
MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

mXtract - Memory Extractor & Analyzer

ROP-based sleep obfuscation to evade memory scanners

A python script developed to process Windows memory images based on triage type.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Tool to make in memory man in the middle

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Dump TeamViewer ID and password from memory. Works much better than other tools.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space