โŒ— MEMFORENSICS
0x00000000 0x40000000 0x80000000 0xC0000000 0xFFFFFFFF

Analyze what was still
in memory.

Upload a memory image or capture live RAM right now โ€” then get a triaged, evidence-ready report in minutes, the same Volatility 3 + heuristic detection pipeline as the CLI and desktop tools.

๐Ÿ”

Automated Triage

Heuristic detection rules flag malware indicators, injected code, suspicious handles, and persistence mechanisms automatically.

โšก

Fast & Local

Runs entirely on your machine โ€” no uploads to external servers. Memory images never leave your environment.

๐Ÿ“

Upload Existing Memory Files

Import pre-collected memory images and continue straight into analysis without recapturing the system.

๐Ÿ’ฝ

Live Memory Capture

Use WinPmem to capture RAM from a running system before analysis, keeping acquisition and triage in one workflow.

๐Ÿ”ง

Deep Mode & YARA

Optional deep analysis (VAD, handles, registry) and custom YARA rule scanning for targeted threat hunting.

๐Ÿ“‹

Evidence-Ready Reports

Generates HTML and JSON reports with risk scores, severity classifications, and artifact evidence for case documentation.

v1.2.0 ยท Windows x64

Download Memory Forensics Toolkit

Standalone portable executable โ€” no installation required. Includes Volatility 3, WinPmem acquisition driver, and the heuristic detection engine.

Download MemForensicsToolkit.exe (38.6 MB)

Verify Integrity

SHA-256: 5325172cbef97ae4d0c7130d197f96967a2c9f96e90121beeab8cabb99c13194
SHA-1: 7dfab2545149541900956d246464dd572f502974