Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
patriot — In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures for endpoint defense and forensic analysis. | Kitploit
Tools/GitHubGitHub/joe-desimone/patriot
Defensive ToolsMemory ForensicsMalware AnalysisBinary AnalysisIncident ResponseAnomaly Detection
GitHubjoe-desimone/patriot

patriot

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures for endpoint defense and forensic analysis.

View Repository
164314 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Patriot

Patriot_missile_launch_b

Small research project for detecting various kinds of in-memory stealth techniques.

Download the latest release here.

The current version supports the following detections:

  • Suspicious CONTEXT structures pointing to VirtualProtect functions. (Targets research by Austin Hudson Foliage and Ekko by Cracked5pider).
  • Validation of MZ/PE headers in memory to detect process hollowing variants.
  • Unbacked executable regions running at high integrity.
  • Modified code used in module stomping/overwriting.
  • Various other anomalies.

image

Download Tool