Comae Toolkit Jun 2026
The is a popular open-source utility suite created by Matthieu Suiche (a renowned security researcher and founder of MoonSols) for analyzing memory dumps.
Keep Volatility in your toolkit for the edge cases. But put the Comae Toolkit at the front of your stack. When the clock is ticking, speed wins.
Whether you are investigating a ransomware attack or hunting for stealthy rootkits, the Comae Toolkit provides the visibility needed to see what is happening in a system’s RAM in real-time. What is the Comae Toolkit?
RAM often holds keys for BitLocker or VeraCrypt while the system is running.
It is widely used in the digital forensics and incident response (DFIR) community. While the is the most famous tool for memory analysis, Comae offers specific strengths, particularly in parsing Windows memory dumps and converting between different dump file formats.

