Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

hollowshunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory pa

memoryBlue Team
Official docs ↗

Platforms: Windows · Last verified September 6, 2026

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Included by default in a FLARE VM install (`hollowshunter` package). See the official VM-Packages listing linked above for details.

Commonly preinstalled on

FLARE VM

Windows-based reverse-engineering and malware-analysis distribution