Memory protection for applications and targeted processes.


Excubits MemProtect LogoMemProtect is a memory protection kernel driver for Windows that can mitigate against in-memory attacks. The driver ensures that any encaged process is not able to operate on memory locations registered to another process. Hence it is not possible to inject code or an executable/library into other processes. It even works if the source application was fully exploited, achieved system level privileges. MemProtect's kernel driver protects all running processes, not just the ones you think of to be protected. After encaging a potentially exploitable program - like a web browser with Flash plugin - such a program cannot access other programs (processes) and thus cannot harvest them in case of exploration to perform code-injection etc. Basically you specify critical process locations (like the path to your browser, e-mail client, office suite, or pdf-reader) that are not allowed to open, read, write, and inject code into all other processes, thus one can protect trustworthy applications from ones that are recently subject to cyber attacks.

Installation and configuration

MemProtect can be installed within a few seconds. In addition, our solution works fully transparent in the background, there is no interaction required. Recognized attacks are logged and can be analyzed later. We implemented no black-box design, you can fully peek into the logs and process them as you want and regarding your needs. For example you can install a watchdog to collect and summarize the log files from all your end-points and can turn each and every Windows client into an active attack detection probe.

Use Cases

MemProtect is ideal for use in centrally administered environments, such as in kiosk systems, business, point-of-sale (POS) systems, libraries, schools, or universities. MemProtect is also suitable for analyzing and protecting offline systems like production plants, as no internet connection is required.


  • Runs entirely in the kernel.
  • System Hardening and In-Memory Threat Mitigation.
  • Use as an early warning system.
  • Use to build proactive forensics IT probes, to investigate incidents timely.
  • Extremely efficient driver using an extremely small binary footprint.
  • No annual fees.
  • Fully offline capable, no signature updates required.
  • Can easily be packed and deployed as an MSI package.
  • Works with all popular versions of Microsoft Windows, incl. Windows Server.
  • Made in Germany.
  • No Ads and no Spyware.
  • Use instantly without pesky registration.
  • No information or forensics back channel to Excubits.

License Pricing / Buy MemProtect

MemProtect only costs 12.00EUR (final price acc. § 19, Abs. 1 UStG), you can directly order it using PayPal. To display the purchase button, please read the Terms of Service and accept them by clicking on the check-box below:

I have read and agree with the Terms of Service and want to buy a license.

System requirements

Windows 7, 8, 8.1 and 10 in its 32-bit and 64-bit versions.

Download MemProtect

Binaries last updated on 2017/08/02

Download the demo version today and start securing your computers today. To display and start the download, please read and accept our Terms of Service below:

I have read and agree with the Terms of Service.