Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
内存取证 | Kitploit
分类

内存取证

用于分析RAM转储以查找正在运行的进程、网络连接和隐藏恶意软件的工具。

最新相关性最受欢迎最近更新
585 结果
内容在请求的语言中不可用。显示英文版本。
Sandb0x-Xtract0r preview

Sandb0x-Xtract0r

GitHubdarnellwashingtonjr94-art/sandb0x-xtract0r

自动化跨平台沙箱,可在隔离的虚拟机/模拟器中引爆可疑文件,捕获网络与内存工件,并生成 LLM 报告。

dynamic-analysis-sandboxingmemory-forensicsnetwork-forensics+3
4
21小时34分前
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

针对 Dropper GCleaner 的逆向工程分析,该恶意软件使用具有弹性的 C2 基础架构、内核驱动程序加载、PowerShell/Conhost 执行以及 .rdata 载荷提取。包含 30+ 个 C2 域名、NtLoadDriver 及完整 API 列表。

privilege-escalationmemory-forensicspersistence-mechanisms+6
12天前
memdumper preview

memdumper

GitHubcenobyte-vincit/memdumper

滥用 macOS 调试器授权和 DYLD_INSERT_LIBRARIES 来转储或搜索正在运行进程的内存,同时将 EDR 归因转移到已签名的辅助二进制文件。

memory-forensicsids-ips-evasioninformation-gathering+4
13天前
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis preview

RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis

GitHubkaandemir993/redline-stealer-c2-defender-bypass-payload-analysis

针对 RedLine Stealer 的逆向工程分析,这是一个基于 .NET 的信息窃取程序,使用 C2 域名(198.46.86.63、tempuri.org),绕过 Windows Defender,并提取 7200 KB 的载荷。

memory-forensicspersistence-mechanismsreverse-engineering+4
17天前
keepass-exfil-forensics preview

keepass-exfil-forensics

GitHubpugazhendii22/keepass-exfil-forensics

适用于 TryHackMe DFIR 挑战的网络取证 Writeup 及配套工具:从 PCAP 流量中逆向还原 hex→Base64→XOR 数据外泄链,然后利用 CVE-2023-32784 从进程内存转储中恢复 KeePass 主密码。

packet-sniffing-analysispassword-crackingmemory-forensics+6
7天前
mal_unpack preview

mal_unpack

GitHubhasherezade/mal_unpack

在受控环境中运行加壳恶意软件,等待其自行解包,从内存中转储 PE 文件和 shellcode,并终止该进程。

dynamic-analysis-sandboxingmemory-forensicsreverse-engineering+2
8274个月前
GarbageMan preview

GarbageMan

GitHubwithsecurelabs/garbageman

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

memory-forensicsreverse-engineeringdata-exfiltration+3
1213年前
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

privilege-escalationvulnerability-scannersmemory-forensics+6
113天前
physmem2profit preview

physmem2profit

GitHubreverseclabs/physmem2profit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

memory-forensicspassword-attacksdata-exfiltration+4
4224年前
memOptix preview

memOptix

GitHubblueteam0ps/memoptix

一个 Jupyter notebook,用于协助分析 Volatility 内存提取框架生成的输出。

memory-forensicsforensicsdigital-forensics+2
983年前
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder

攻击性令牌收集实用工具,可搜索 x64 进程内存和 TokenBroker 缓存文件,在 Office、Edge、Teams 和 PowerShell 中查找 Azure AD/O365 JWT 令牌。

memory-forensicspost-exploitationpenetration-testing+3
1093年前
Awesome-CobaltStrike preview

Awesome-CobaltStrike

GitHubzer0yu/awesome-cobaltstrike

List of Awesome CobaltStrike Resources

memory-forensicsids-ips-evasionlateral-movement+7
4.4k2年前
truffleproc preview

truffleproc

GitHubcontrolplaneio/truffleproc

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

memory-forensicsdebuggersdigital-forensics+1
1283年前
TickTock preview

TickTock

GitHubwithsecurelabs/ticktock

枚举 Windows 定时器队列计时器,以检测 Ekko 睡眠混淆,辅助内存取证和恶意软件分析,识别规避检测的内存驻留威胁。

defensive-toolsmemory-forensicsmalware-analysis
1133年前
SuperMem preview

SuperMem

GitHubcrowdstrike/supermem

一个基于分类类型处理 Windows 内存镜像的 Python 脚本。

memory-forensicsforensicsmalware-analysis+2
2672年前
GoTEE-example preview

GoTEE-example

GitHubusbarmory/gotee-example

GoTEE - example application

embedded-systems-securitymemory-forensicsdebuggers+2
174个月前
kdmp-parser preview

kdmp-parser

GitHub0vercl0k/kdmp-parser

一个带有 Python 3 绑定的 Windows 内核转储 C++ 解析器库。

memory-forensicsforensicsdigital-forensics+1
21110个月前
windbg_js_scripts preview

windbg_js_scripts

GitHubhugsy/windbg_js_scripts

Toy scripts for playing with WinDbg JS API

memory-forensicsdynamic-code-analysisreverse-engineering+3
2442年前
上一页12…33下一页