Here are
23 public repositories
matching this topic...
Educational, CTF-styled labs for individuals interested in Memory Forensics
WinDBG Anti-RootKit Extension
AVML - Acquire Volatile Memory for Linux
Updated
Aug 18, 2020
Rust
Data Visualization Plugin for IDA Pro
Updated
Jun 9, 2020
Python
Allows you to quickly query a Windows machine for RAM artifacts
Updated
Jul 17, 2020
Python
Hyper-V Research is trendy now
A short and small memory forensics helper.
Updated
Oct 18, 2017
Python
A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University
Development guide for Volatility Plugins
A script to assist in processing forensic RAM captures for malware triage
Updated
Feb 27, 2020
Shell
Tool to extract the kallsyms (System.map) from a memory dump
Updated
Jul 29, 2020
Python
Minion rules for DFIR work.
Learning volatility plugins.
Updated
Feb 23, 2020
Python
Not Only Forensics Toolkit
Updated
Apr 8, 2018
PowerShell
Updated
Nov 2, 2018
Python
Volatility profile for uclinux
Updated
Jun 19, 2020
Python
Introducing the Temporal Dimension to Memory Forensics - ACM Transactions on Privacy and Security 2019
Updated
Jul 15, 2019
Python
The CARLA driving simulator is a great way to cheaply model a self-driving car. These plugins are perfect for mining vehicle data after acquiring a memory dump.
Updated
Jul 30, 2020
Python
C# Implementation of Jared Atkinson's Get-InjectedThread.ps1
Updated
Jun 19, 2017
Python
Volatility plugin to yield and compare similarity digest of modules on execution.
Updated
Aug 6, 2020
Python
Improve this page
Add a description, image, and links to the
memory-forensics
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
memory-forensics
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.