8 repository-uri
Utilities for capturing volatile memory and system artifacts.
Explore 8 awesome GitHub repositories matching part of an awesome list · Data Acquisition. Refine with filters or upvote what's useful.
pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and conducting remote volatile memory forensics. It functions as a hardware memory acquisition tool and a PCIe DMA attack framework designed to read and write remote system memory via direct hardware interfaces. The project provides capabilities for capturing and displaying raw transaction layer packets from the PCIe bus and mounting live RAM as local drives for analysis. It enables the modification of system memory signatures and the execution of shellcode or implants within the kernel wi
Extracts data from live sessions or crash files using hardware or software agents for volatile data analysis.
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Tool for host-based state collection using custom queries.
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisitio
Kernel module for acquiring volatile memory from Linux devices.
AVML - Acquire Volatile Memory for Linux
Portable tool for acquiring volatile memory on Linux.
Extract files from Apple devices on Windows, Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and "advanced logical backups"
Tool for extracting data from Apple mobile devices.
🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
Customizable agent for collecting forensic artifacts across platforms.
macOS forensic acquisition made simple
Graphical interface for logical acquisition of Mac devices.
Extract common Windows artifacts from source images and VSCs
Tool for extracting common Windows artifacts from images.