14 रिपॉजिटरी
Tools for dissecting malware in memory images or running systems.
Explore 14 awesome GitHub repositories matching part of an awesome list · Memory Forensics. Refine with filters or upvote what's useful.
This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis
Automates the installation and configuration of specialized frameworks for analyzing system memory dumps.
Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com
Standard framework for memory forensic investigations.
MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory forensic virtual file system, mapping physical memory and kernel objects into a virtual directory structure that allows users to analyze system artifacts using standard file system tools. The project distinguishes itself by providing a virtual file system for memory forensics, enabling the browsing and querying of physical memory as read-only files and folders. It also incorporates a Yara-based memory scanner to identify malware signatures and injected code within physical memor
Virtual file system for accessing physical memory.
Rekall Memory Forensic Framework
Framework for advanced memory forensic analysis.
Extracts passwords from a KeePass 2.x database, directly from memory.
Tool for extracting passwords from memory.
WinDBG Anti-RootKit Extension
Anti-rootkit extension for the windows debugger.
Web App for Volatility framework
Web-based interface for the memory forensic framework.
inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques
High-speed memory analysis framework for Windows x64.
The Volatility Collaborative GUI
Collaborative framework for forensic memory dump analysis.
Web interface for the Volatility Memory Forensics Framework
Web interface for the volatility memory forensics framework.
Differential Analysis of Malware in Memory
Differential analysis of malware in memory using volatility.
VolDiff: Malware Memory Footprint Analysis based on Volatility
Compares memory images before and after malware execution.
A short and small memory forensics helper.
Automates volatility analysis and generates readable reports.
Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.
Script for automating various memory-based analysis tasks.