awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 مستودعات

Awesome GitHub RepositoriesMemory Forensics

Tools for dissecting malware in memory images or running systems.

Explore 14 awesome GitHub repositories matching part of an awesome list · Memory Forensics. Refine with filters or upvote what's useful.

Awesome Memory Forensics GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • zardus/ctf-toolsالصورة الرمزية لـ zardus

    zardus/ctf-tools

    9,434عرض على GitHub↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Automates the installation and configuration of specialized frameworks for analyzing system memory dumps.

    Shell
    عرض على GitHub↗9,434
  • volatilityfoundation/volatilityالصورة الرمزية لـ volatilityfoundation

    volatilityfoundation/volatility

    7,971عرض على GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Standard framework for memory forensic investigations.

    Pythonmalwarememorypython
    عرض على GitHub↗7,971
  • ufrisk/memprocfsالصورة الرمزية لـ ufrisk

    ufrisk/MemProcFS

    4,202عرض على GitHub↗

    MemProcFS هي أداة تحليل ذاكرة متطايرة ونظام الحصول على الذاكرة عبر الأنظمة الأساسية. تعمل كنظام ملفات افتراضي لطب الشرعي للذاكرة، حيث تقوم بتعيين الذاكرة الفعلية وكائنات النواة في هيكل دليل افتراضي يسمح للمستخدمين بتحليل آثار النظام باستخدام أدوات نظام الملفات القياسية. يتميز المشروع بتوفير نظام ملفات افتراضي لطب الشرعي للذاكرة، مما يتيح تصفح والاستعلام عن الذاكرة الفعلية كملفات ومجلدات للقراءة فقط. كما يدمج ماسح ذاكرة يعتمد على Yara لتحديد توقيعات البرامج الضارة والكود المحقون داخل الذاكرة الفعلية. يغطي المحرك مجموعة واسعة من إمكانيات الطب الشرعي، بما في ذلك فحص العمليات والخيوط، وإدراج اتصالات الشبكة، وتحليل سجل Windows. يدعم استيعاب البيانات من الأنظمة الحية، وتفريغ الأعطال، والأجهزة الافتراضية، مع توفير حل الرموز لترجمة عناوين الذاكرة الخام إلى أسماء ذات معنى. يتم دعم التكامل من خلال واجهة برمجية متعددة اللغات وأغلفة مكتبة أصلية لـ C و Java، بالإضافة إلى برمجة Python بدون رأس لسير العمل المؤتمت.

    Virtual file system for accessing physical memory.

    C
    عرض على GitHub↗4,202
  • google/rekallالصورة الرمزية لـ google

    google/rekall

    1,998عرض على GitHub↗

    Rekall Memory Forensic Framework

    Framework for advanced memory forensic analysis.

    Python
    عرض على GitHub↗1,998
  • denandz/keefarceالصورة الرمزية لـ denandz

    denandz/KeeFarce

    1,021عرض على GitHub↗

    Extracts passwords from a KeePass 2.x database, directly from memory.

    Tool for extracting passwords from memory.

    C++
    عرض على GitHub↗1,021
  • swwwolf/wdbgarkالصورة الرمزية لـ swwwolf

    swwwolf/wdbgark

    642عرض على GitHub↗

    WinDBG Anti-RootKit Extension

    Anti-rootkit extension for the windows debugger.

    C++
    عرض على GitHub↗642
  • kevthehermit/volutilityالصورة الرمزية لـ kevthehermit

    kevthehermit/VolUtility

    387عرض على GitHub↗

    Web App for Volatility framework

    Web-based interface for the memory forensic framework.

    Python
    عرض على GitHub↗387
  • shanek2/invtero.netالصورة الرمزية لـ ShaneK2

    ShaneK2/inVtero.net

    296عرض على GitHub↗

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    High-speed memory analysis framework for Windows x64.

    C#
    عرض على GitHub↗296
  • ldo-cert/orochiالصورة الرمزية لـ LDO-CERT

    LDO-CERT/orochi

    269عرض على GitHub↗

    The Volatility Collaborative GUI

    Collaborative framework for forensic memory dump analysis.

    JavaScript
    عرض على GitHub↗269
  • jameshabben/evolveالصورة الرمزية لـ JamesHabben

    JamesHabben/evolve

    259عرض على GitHub↗

    Web interface for the Volatility Memory Forensics Framework

    Web interface for the volatility memory forensics framework.

    JavaScript
    عرض على GitHub↗259
  • 504ensicslabs/dammالصورة الرمزية لـ 504ensicsLabs

    504ensicsLabs/DAMM

    214عرض على GitHub↗

    Differential Analysis of Malware in Memory

    Differential analysis of malware in memory using volatility.

    Python
    عرض على GitHub↗214
  • aim4r/voldiffالصورة الرمزية لـ aim4r

    aim4r/VolDiff

    195عرض على GitHub↗

    VolDiff: Malware Memory Footprint Analysis based on Volatility

    Compares memory images before and after malware execution.

    Python
    عرض على GitHub↗195
  • ytisf/muninnالصورة الرمزية لـ ytisf

    ytisf/muninn

    52عرض على GitHub↗

    A short and small memory forensics helper.

    Automates volatility analysis and generates readable reports.

    Python
    عرض على GitHub↗52
  • sketchymoose/totalrecallالصورة الرمزية لـ sketchymoose

    sketchymoose/TotalRecall

    49عرض على GitHub↗

    Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

    Script for automating various memory-based analysis tasks.

    Python
    عرض على GitHub↗49
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Memory Forensics