Here are
33 public repositories
matching this topic...
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Educational, CTF-styled labs for individuals interested in Memory Forensics
Updated
Mar 8, 2021
Shell
WinDBG Anti-RootKit Extension
AVML - Acquire Volatile Memory for Linux
Updated
Sep 21, 2021
Rust
Data Visualization Plugin for IDA Pro
Updated
May 7, 2021
Python
Dynamic unpacker based on PE-sieve
Allows you to quickly query a Windows machine for RAM artifacts
Updated
Jul 17, 2020
Python
Hyper-V Research is trendy now
A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
C# Implementation of Jared Atkinson's Get-InjectedThread.ps1
A short and small memory forensics helper.
Updated
Oct 18, 2017
Python
Development guide for Volatility Plugins
A script to assist in processing forensic RAM captures for malware triage
Updated
Feb 4, 2021
Shell
Tool to extract the kallsyms (System.map) from a memory dump
Updated
Jun 18, 2021
Python
Minion rules for DFIR work.
Learning volatility plugins.
Updated
Feb 16, 2021
Python
Not Only Forensics Toolkit
Updated
Apr 8, 2018
PowerShell
My digital forensics notebook
Volatility plugin to yield and compare similarity digest of modules on execution.
Updated
Aug 11, 2021
Python
Updated
Nov 2, 2018
Python
My Linux profiles built for Volatility 2/3
Volatility profile for uclinux
Updated
Jun 19, 2020
Python
Introducing the Temporal Dimension to Memory Forensics - ACM Transactions on Privacy and Security 2019
Updated
Jul 15, 2019
Python
Data structure detection with neural networks.
Updated
Sep 19, 2021
Python
Volatility plugin to obtain the number of the resident memory pages per module (exe or dll) and per driver from a Windows memory dump.
Updated
May 11, 2021
Python
Volatility plugins to recover ML model attributes from memory images
Updated
Aug 10, 2021
Python
Improve this page
Add a description, image, and links to the
memory-forensics
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
memory-forensics
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.