LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it…
الميزات الرئيسية لـ 504ensicslabs/lime هي: Dynamic Analysis and Debugging, Dynamic Analysis, Dynamic Analysis Tools, Data Acquisition, Digital Forensics, Forensic Analysis, Memory Analysis Tools, Security And Forensics.
تشمل البدائل مفتوحة المصدر لـ 504ensicslabs/lime: volatilityfoundation/volatility — Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from… rurik/noriben — Noriben - Portable, Simple, Malware Analysis Sandbox. microsoft/avml — AVML - Acquire Volatile Memory for Linux. velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… ufrisk/memprocfs — MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory…
Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com
Noriben - Portable, Simple, Malware Analysis Sandbox
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro