awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Forensique numérique et analyse mémoire

Classement mis à jour le 30 juin 2026

For un outil pour la criminalistique numérique et l'analyse mémoire, the strongest matches are shanek2/invtero.net (inVtero), ufrisk/memprocfs (MemProcFS is a memory forensics tool that mounts memory) and volatilityfoundation/volatility (Volatility is the leading open-source memory analysis framework for). kevthehermit/volutility and aim4r/voldiff round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Logiciels open source pour l'investigation numérique, l'analyse de mémoire vive et la réponse aux incidents (forensics).

Forensique numérique et analyse mémoire

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • shanek2/invtero.netAvatar de ShaneK2

    ShaneK2/inVtero.net

    296Voir sur GitHub↗

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    inVtero.net is a high-speed memory analysis tool using virtual machine introspection to find processes and hypervisors in memory dumps, fitting the digital forensics and memory analysis category, but it focuses solely on analysis and does not cover memory acquisition, timeline analysis, or cross-platform support.

    C#Memory Analysis ToolsMemory ForensicsMemory Forensics
    Voir sur GitHub↗296
  • ufrisk/memprocfsAvatar de ufrisk

    ufrisk/MemProcFS

    4,202Voir sur GitHub↗

    MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory forensic virtual file system, mapping physical memory and kernel objects into a virtual directory structure that allows users to analyze system artifacts using standard file system tools. The project distinguishes itself by providing a virtual file system for memory forensics, enabling the browsing and querying of physical memory as read-only files and folders. It also incorporates a Yara-based memory scanner to identify malware signatures and injected code within physical memor

    MemProcFS is a memory forensics tool that mounts memory images as a browsable file system for analysis, fitting the digital forensics and memory analysis category, though it focuses on analysis rather than live acquisition.

    CMemory AnalysisMemory Analysis ToolsMemory Forensics
    Voir sur GitHub↗4,202
  • volatilityfoundation/volatilityAvatar de volatilityfoundation

    volatilityfoundation/volatility

    7,971Voir sur GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Volatility is the leading open-source memory analysis framework for extracting and examining evidence from RAM dumps, but it focuses on analysis rather than live acquisition, so it only partly covers the full acquisition-and-analysis workflow you described.

    PythonMemory AnalysisMemory Analysis ToolsMemory Forensics
    Voir sur GitHub↗7,971
  • kevthehermit/volutilityAvatar de kevthehermit

    kevthehermit/VolUtility

    387Voir sur GitHub↗

    Web App for Volatility framework

    This is a web-based interface for the Volatility memory analysis framework, enabling analysis of memory dumps through a browser, but it does not include memory acquisition or a command-line interface, so it covers only part of the search requirements.

    PythonMemory ForensicsMemory Forensics
    Voir sur GitHub↗387
  • aim4r/voldiffAvatar de aim4r

    aim4r/VolDiff

    195Voir sur GitHub↗

    VolDiff: Malware Memory Footprint Analysis based on Volatility

    VolDiff is a specialized tool for malware memory footprint analysis that relies on Volatility, so it fits the memory analysis aspect of your search but does not handle memory acquisition, file carving, or timeline analysis.

    PythonMemory Analysis ToolsMemory Forensics
    Voir sur GitHub↗195
  • google/rekallAvatar de google

    google/rekall

    1,998Voir sur GitHub↗

    Rekall Memory Forensic Framework

    Rekall is a memory forensic framework that focuses on analyzing RAM dumps, directly matching the core need for digital forensics and memory analysis, though its capabilities for live acquisition are secondary and it is not Volatility-compatible.

    PythonMemory ForensicsMemory Forensics
    Voir sur GitHub↗1,998
  • mkorman90/volatilitybotAvatar de mkorman90

    mkorman90/VolatilityBot

    268Voir sur GitHub↗

    VolatilityBot – An automated memory analyzer for malware samples and memory dumps

    VolatilityBot automates memory dump analysis using Volatility, fitting the memory analysis need of digital forensics, but it does not handle live memory acquisition itself.

    PythonMemory Analysis Tools
    Voir sur GitHub↗268
  • volatilityfoundation/volatility3Avatar de volatilityfoundation

    volatilityfoundation/volatility3

    4,192Voir sur GitHub↗

    Volatility3 is a memory forensics framework and analysis tool used to parse volatile memory dumps. It extracts digital artifacts and reconstructs the runtime state of a system to recover process information, network artifacts, and other forensic evidence. The system functions as a plugin-based forensic engine and an operating system symbol resolver. It maps raw memory addresses to known system structures using symbol tables and translation layers, and provides an extensible architecture for creating custom scanners and renderers. The framework includes a command-line memory explorer for real

    Volatility 3 is the premier open-source memory analysis framework for digital forensics, supporting multiple image formats and CLI workflows — it fits your need for analyzing RAM dumps, though you will need a separate tool like LiME or winpmem for live acquisition.

    PythonMemory Analysis ToolsMemory Forensics
    Voir sur GitHub↗4,192
  • google/grrAvatar de google

    google/grr

    5,074Voir sur GitHub↗

    GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro

    GRR is a distributed incident response and remote forensics framework that collects and analyzes volatile memory and system artifacts across a fleet, making it a relevant digital forensics tool, though its broader orchestration focus means it is not a dedicated memory analysis tool like Volatility.

    PythonForensic Event Timelines
    Voir sur GitHub↗5,074
  • velocidex/velociraptorAvatar de Velocidex

    Velocidex/velociraptor

    3,769Voir sur GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Velociraptor is a general-purpose digital forensics and incident response platform that can capture and analyze endpoint data, but it is not specifically specialized in volatile memory acquisition or Volatility-compatible analysis — while it covers many DFIR tasks, its focus is broader, so it fits the stated category but with less emphasis on the memory-analysis aspect you need.

    GoMemory Forensics
    Voir sur GitHub↗3,769
Comparez le top 10 en un coup d'œil
DépôtStarsLangageLicenceDernier push
shanek2/invtero.net296C#AGPL-3.030 sept. 2023
ufrisk/memprocfs4.2KCAGPL-3.02 juin 2026
volatilityfoundation/volatility8KPythongpl-2.016 mai 2025
kevthehermit/volutility387PythonGPL-3.013 janv. 2026
aim4r/voldiff195PythonBSD-2-Clause12 sept. 2017
google/rekall2KPythonGPL-2.018 oct. 2020
mkorman90/volatilitybot268PythonMIT15 juin 2021
volatilityfoundation/volatility34.2KPythonNOASSERTION26 mai 2026
google/grr5.1KPythonApache-2.012 mai 2026
velocidex/velociraptor3.8KGoother20 févr. 2026

Related searches

  • Forensique numérique et réponse aux incidents
  • outil de triage forensique
  • outil de carving et de récupération de fichiers
  • outil d'analyse forensique pour navigateur
  • Analyse de malware et ingénierie inverse
  • désassembleur interactif
  • outil de timeline forensique
  • toolkit de dépaquetage de binaires