8 Repos
Tools for investigating artifacts, memory, and file system integrity.
Explore 8 awesome GitHub repositories matching part of an awesome list · Forensics Analysis. Refine with filters or upvote what's useful.
This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis
Ships a collection of utilities for memory forensics, XOR data decoding, and binary analysis.
Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com
Framework for investigating memory dumps.
dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe
Hosts communication through DNS tunnels.
Adversary tradecraft detection, protection, and hunting
Exploration and tracing tool for the Windows kernel.
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
Rips web-accessible distributed version control systems.
Tracking history of USB events on GNU/Linux
Tracks USB device history and artifacts on Linux.
Automatically exported from code.google.com/p/creddump
Extracts credentials from Windows memory dumps.
Cross-platform, open-source shellbag parser
Investigates Windows shellbag artifacts.