Skip to main content

memforensics

Offline memory-image forensics for authorized pentesting and CTF — extract credentials and artifacts from RAM dumps, VM memory snapshots, and lsass minidumps with volatility3. Use when loot includes a memory image (.vmem/.vmsn/.dmp/.raw/hiberfil.sys) or an lsass dump and you need hashes, LSA secrets, cached domain creds, plaintext passwords, or process/registry artifacts out of it. Triggers on ".vmem", "memory dump", "RAM image", "VM snapshot", "lsass dump", "hiberfil", "memory forensics", "volatility", "extract creds from memory", "what's in this dump".

Jump to install

Source facts

Repository
dariushoule/roorecon
Last source activity
June 14, 2026 at 22:40
Detected SKILL.md language
English
Stars
1
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.