
aes-finder
Utility to find AES keys in running processes

Utility to find AES keys in running processes

Process heap analysis framework - Windows/Linux - record type inference and forensics

Dumping processes using the power of kernel space !

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Dump cookies and credentials directly from Chrome/Edge process memory

A memory-based evasion technique which makes shellcode invisible from process start to end.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…