awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 repositorios

Awesome GitHub RepositoriesMemory Forensics

Tools for dissecting malware in memory images or running systems.

Explore 14 awesome GitHub repositories matching part of an awesome list · Memory Forensics. Refine with filters or upvote what's useful.

Awesome Memory Forensics GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • zardus/ctf-toolsAvatar de zardus

    zardus/ctf-tools

    9,434Ver en GitHub↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Automates the installation and configuration of specialized frameworks for analyzing system memory dumps.

    Shell
    Ver en GitHub↗9,434
  • volatilityfoundation/volatilityAvatar de volatilityfoundation

    volatilityfoundation/volatility

    7,971Ver en GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Standard framework for memory forensic investigations.

    Pythonmalwarememorypython
    Ver en GitHub↗7,971
  • ufrisk/memprocfsAvatar de ufrisk

    ufrisk/MemProcFS

    4,202Ver en GitHub↗

    MemProcFS es una herramienta de análisis de memoria volátil y un sistema de adquisición de memoria multiplataforma. Funciona como un sistema de archivos virtual de análisis forense de memoria, mapeando la memoria física y los objetos del kernel en una estructura de directorio virtual que permite a los usuarios analizar artefactos del sistema utilizando herramientas estándar de sistema de archivos. El proyecto se distingue por proporcionar un sistema de archivos virtual para análisis forense de memoria, permitiendo navegar y consultar la memoria física como archivos y carpetas de solo lectura. También incorpora un escáner de memoria basado en Yara para identificar firmas de malware y código inyectado dentro de la memoria física. El motor cubre una amplia gama de capacidades forenses, incluyendo inspección de procesos e hilos, listado de conexiones de red y análisis del registro de Windows. Admite la ingesta de datos desde sistemas en vivo, volcados de memoria (crash dumps) y máquinas virtuales, mientras proporciona resolución de símbolos para traducir direcciones de memoria sin procesar en nombres significativos. La integración se admite mediante una interfaz programática multilingüe y envoltorios de biblioteca nativos para C y Java, así como scripting en Python para flujos de trabajo automatizados.

    Virtual file system for accessing physical memory.

    C
    Ver en GitHub↗4,202
  • google/rekallAvatar de google

    google/rekall

    1,998Ver en GitHub↗

    Rekall Memory Forensic Framework

    Framework for advanced memory forensic analysis.

    Python
    Ver en GitHub↗1,998
  • denandz/keefarceAvatar de denandz

    denandz/KeeFarce

    1,021Ver en GitHub↗

    Extracts passwords from a KeePass 2.x database, directly from memory.

    Tool for extracting passwords from memory.

    C++
    Ver en GitHub↗1,021
  • swwwolf/wdbgarkAvatar de swwwolf

    swwwolf/wdbgark

    642Ver en GitHub↗

    WinDBG Anti-RootKit Extension

    Anti-rootkit extension for the windows debugger.

    C++
    Ver en GitHub↗642
  • kevthehermit/volutilityAvatar de kevthehermit

    kevthehermit/VolUtility

    387Ver en GitHub↗

    Web App for Volatility framework

    Web-based interface for the memory forensic framework.

    Python
    Ver en GitHub↗387
  • shanek2/invtero.netAvatar de ShaneK2

    ShaneK2/inVtero.net

    296Ver en GitHub↗

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    High-speed memory analysis framework for Windows x64.

    C#
    Ver en GitHub↗296
  • ldo-cert/orochiAvatar de LDO-CERT

    LDO-CERT/orochi

    269Ver en GitHub↗

    The Volatility Collaborative GUI

    Collaborative framework for forensic memory dump analysis.

    JavaScript
    Ver en GitHub↗269
  • jameshabben/evolveAvatar de JamesHabben

    JamesHabben/evolve

    259Ver en GitHub↗

    Web interface for the Volatility Memory Forensics Framework

    Web interface for the volatility memory forensics framework.

    JavaScript
    Ver en GitHub↗259
  • 504ensicslabs/dammAvatar de 504ensicsLabs

    504ensicsLabs/DAMM

    214Ver en GitHub↗

    Differential Analysis of Malware in Memory

    Differential analysis of malware in memory using volatility.

    Python
    Ver en GitHub↗214
  • aim4r/voldiffAvatar de aim4r

    aim4r/VolDiff

    195Ver en GitHub↗

    VolDiff: Malware Memory Footprint Analysis based on Volatility

    Compares memory images before and after malware execution.

    Python
    Ver en GitHub↗195
  • ytisf/muninnAvatar de ytisf

    ytisf/muninn

    52Ver en GitHub↗

    A short and small memory forensics helper.

    Automates volatility analysis and generates readable reports.

    Python
    Ver en GitHub↗52
  • sketchymoose/totalrecallAvatar de sketchymoose

    sketchymoose/TotalRecall

    49Ver en GitHub↗

    Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

    Script for automating various memory-based analysis tasks.

    Python
    Ver en GitHub↗49
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Memory Forensics