Here are
41 public repositories
matching this topic...
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Educational, CTF-styled labs for individuals interested in Memory Forensics
Updated
Mar 8, 2021
Shell
WinDBG Anti-RootKit Extension
AVML - Acquire Volatile Memory for Linux
Dynamic unpacker based on PE-sieve
Data Visualization Plugin for IDA Pro
Updated
Dec 17, 2021
Python
Allows you to quickly query a Windows machine for RAM artifacts
Updated
Jul 17, 2020
Python
Hyper-V Research is trendy now
Rip Raw is a small tool to analyse the memory of compromised Linux systems.
Updated
Jan 31, 2022
Python
A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
A short and small memory forensics helper.
Updated
Oct 18, 2017
Python
C# Implementation of Jared Atkinson's Get-InjectedThread.ps1
A script to assist in processing forensic RAM captures for malware triage
Updated
Feb 4, 2021
Shell
Development guide for Volatility Plugins
Tool to extract the kallsyms (System.map) from a memory dump
Updated
Jun 18, 2021
Python
A suite of Volatility 3 plugins for memory forensics of Docker containers
Updated
Apr 13, 2022
Python
Virtual Machine Introspection (VMI) for memory forensics and machine-learning.
Learning volatility plugins.
Updated
Feb 16, 2021
Python
Minion rules for DFIR work.
My digital forensics notebook
My Linux profiles built for Volatility 2/3
Not Only Forensics Toolkit
Updated
Apr 8, 2018
PowerShell
Updated
Nov 2, 2018
Python
Volatility plugin to yield and compare similarity digest of modules on execution.
Updated
Dec 29, 2021
Python
Volatility profile for uclinux
Updated
Jun 19, 2020
Python
Tool to extract contents from the memory of Windows systems.
Introducing the Temporal Dimension to Memory Forensics - ACM Transactions on Privacy and Security 2019
Updated
Jul 15, 2019
Python
Improve this page
Add a description, image, and links to the
memory-forensics
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
memory-forensics
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.