
In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures for endpoint defense and forensic analysis.

Small research project for detecting various kinds of in-memory stealth techniques.
Download the latest release here.
The current version supports the following detections:
