MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory forensic virtual file system, mapping physical memory and kernel objects into a virtual directory structure that allows users to analyze system artifacts using standard file system tools. The project distinguishes itself by providing a virtual file system for memory forensics, enabling the browsing and querying of physical memory as read-only files and folders. It also incorporates a Yara-based memory scanner to identify malware signatures and injected code within physical memor
Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com
Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Volatility3 एक मेमोरी फॉरेंसिक फ्रेमवर्क और विश्लेषण टूल है जिसका उपयोग वोलेटाइल मेमोरी डंप को पार्स करने के लिए किया जाता है। यह डिजिटल आर्टिफैक्ट्स निकालता है और प्रोसेस जानकारी, नेटवर्क आर्टिफैक्ट्स और अन्य फॉरेंसिक साक्ष्य को पुनर्प्राप्त करने के लिए सिस्टम की रनटाइम स्थिति को पुनर्निर्माण करता है।
volatilityfoundation/volatility3 की मुख्य विशेषताएं हैं: Digital Forensics, Symbol Table Resolution, Virtual Address Translators, Kernel Symbol Resolution, Memory Address Translation Layers, Volatile Memory Ingestion, Memory Forensics, Forensic Artifact Extraction।
volatilityfoundation/volatility3 के ओपन-सोर्स विकल्पों में शामिल हैं: ufrisk/memprocfs — MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory… volatilityfoundation/volatility — Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… th-ch/youtube-music — This project is a desktop client for YouTube Music, serving as a cross-platform wrapper that encapsulates the… dthree/vorpal — Vorpal is a Node.js interactive CLI framework and terminal user interface library used to build extensible…