Upload a memory image or capture live RAM right now โ then get a triaged, evidence-ready report in minutes, the same Volatility 3 + heuristic detection pipeline as the CLI and desktop tools.
Heuristic detection rules flag malware indicators, injected code, suspicious handles, and persistence mechanisms automatically.
Runs entirely on your machine โ no uploads to external servers. Memory images never leave your environment.
Import pre-collected memory images and continue straight into analysis without recapturing the system.
Use WinPmem to capture RAM from a running system before analysis, keeping acquisition and triage in one workflow.
Optional deep analysis (VAD, handles, registry) and custom YARA rule scanning for targeted threat hunting.
Generates HTML and JSON reports with risk scores, severity classifications, and artifact evidence for case documentation.
Standalone portable executable โ no installation required. Includes Volatility 3, WinPmem acquisition driver, and the heuristic detection engine.
Download MemForensicsToolkit.exe (38.6 MB)5325172cbef97ae4d0c7130d197f96967a2c9f96e90121beeab8cabb99c13194
7dfab2545149541900956d246464dd572f502974