


🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

A Windows kernel dump C++ parser library with Python 3 bindings.

Volatility Explorer Suit (volatility 3)

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

A python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.


ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

linux security checks

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

A Linux version of the ProcDump Sysinternals tool

Memory Debugger for Windows, Linux, Mac, and Android

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

mXtract - Memory Extractor & Analyzer

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.