mimikittenz, a PowerShell tool to extract plain-text passwords from memory

The tool utilizes the Windows function ReadProcessMemory() in order to extract plain-text passwords from various target processes mimikittenz (the younger brother of Mimikatz?) provides a user-level extraction tool for sensitive data, focusing on running process memory address space: once a process is killed it’s memory ‘should’ be cleaned up and …

Rekall, a framework for memory forensic

An end-to-end solution to incident responders and forensic analysts Rekall is a collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory samples. The extraction techniques are performed completely independent of the system being investigated but offer visibilty into the …