awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 repository-uri

Awesome GitHub RepositoriesMemory Forensics

Tools for dissecting malware in memory images or running systems.

Explore 14 awesome GitHub repositories matching part of an awesome list · Memory Forensics. Refine with filters or upvote what's useful.

Awesome Memory Forensics GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • zardus/ctf-toolsAvatar zardus

    zardus/ctf-tools

    9,434Vezi pe GitHub↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Automates the installation and configuration of specialized frameworks for analyzing system memory dumps.

    Shell
    Vezi pe GitHub↗9,434
  • volatilityfoundation/volatilityAvatar volatilityfoundation

    volatilityfoundation/volatility

    7,971Vezi pe GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Standard framework for memory forensic investigations.

    Pythonmalwarememorypython
    Vezi pe GitHub↗7,971
  • ufrisk/memprocfsAvatar ufrisk

    ufrisk/MemProcFS

    4,202Vezi pe GitHub↗

    MemProcFS este un instrument de analiză a memoriei volatile și un sistem de achiziție a memoriei cross-platform. Acesta funcționează ca un sistem de fișiere virtual pentru criminalistica memoriei, mapând memoria fizică și obiectele kernel-ului într-o structură de directoare virtuală care permite utilizatorilor să analizeze artefactele sistemului folosind instrumente standard de sistem de fișiere. Proiectul se distinge prin furnizarea unui sistem de fișiere virtual pentru criminalistica memoriei, permițând navigarea și interogarea memoriei fizice ca fișiere și foldere read-only. De asemenea, încorporează un scaner de memorie bazat pe Yara pentru a identifica semnăturile malware și codul injectat în memoria fizică. Motorul acoperă o gamă largă de capabilități criminalistice, inclusiv inspecția proceselor și thread-urilor, listarea conexiunilor de rețea și analiza registry-ului Windows. Suportă ingestia de date din sisteme live, crash dump-uri și mașini virtuale, oferind în același timp rezoluția simbolurilor pentru a traduce adresele brute de memorie în nume semnificative. Integrarea este suportată printr-o interfață programatică multi-limbaj și wrappere de biblioteci native pentru C și Java, precum și scripting Python headless pentru fluxuri de lucru automatizate.

    Virtual file system for accessing physical memory.

    C
    Vezi pe GitHub↗4,202
  • google/rekallAvatar google

    google/rekall

    1,998Vezi pe GitHub↗

    Rekall Memory Forensic Framework

    Framework for advanced memory forensic analysis.

    Python
    Vezi pe GitHub↗1,998
  • denandz/keefarceAvatar denandz

    denandz/KeeFarce

    1,021Vezi pe GitHub↗

    Extracts passwords from a KeePass 2.x database, directly from memory.

    Tool for extracting passwords from memory.

    C++
    Vezi pe GitHub↗1,021
  • swwwolf/wdbgarkAvatar swwwolf

    swwwolf/wdbgark

    642Vezi pe GitHub↗

    WinDBG Anti-RootKit Extension

    Anti-rootkit extension for the windows debugger.

    C++
    Vezi pe GitHub↗642
  • kevthehermit/volutilityAvatar kevthehermit

    kevthehermit/VolUtility

    387Vezi pe GitHub↗

    Web App for Volatility framework

    Web-based interface for the memory forensic framework.

    Python
    Vezi pe GitHub↗387
  • shanek2/invtero.netAvatar ShaneK2

    ShaneK2/inVtero.net

    296Vezi pe GitHub↗

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    High-speed memory analysis framework for Windows x64.

    C#
    Vezi pe GitHub↗296
  • ldo-cert/orochiAvatar LDO-CERT

    LDO-CERT/orochi

    269Vezi pe GitHub↗

    The Volatility Collaborative GUI

    Collaborative framework for forensic memory dump analysis.

    JavaScript
    Vezi pe GitHub↗269
  • jameshabben/evolveAvatar JamesHabben

    JamesHabben/evolve

    259Vezi pe GitHub↗

    Web interface for the Volatility Memory Forensics Framework

    Web interface for the volatility memory forensics framework.

    JavaScript
    Vezi pe GitHub↗259
  • 504ensicslabs/dammAvatar 504ensicsLabs

    504ensicsLabs/DAMM

    214Vezi pe GitHub↗

    Differential Analysis of Malware in Memory

    Differential analysis of malware in memory using volatility.

    Python
    Vezi pe GitHub↗214
  • aim4r/voldiffAvatar aim4r

    aim4r/VolDiff

    195Vezi pe GitHub↗

    VolDiff: Malware Memory Footprint Analysis based on Volatility

    Compares memory images before and after malware execution.

    Python
    Vezi pe GitHub↗195
  • ytisf/muninnAvatar ytisf

    ytisf/muninn

    52Vezi pe GitHub↗

    A short and small memory forensics helper.

    Automates volatility analysis and generates readable reports.

    Python
    Vezi pe GitHub↗52
  • sketchymoose/totalrecallAvatar sketchymoose

    sketchymoose/TotalRecall

    49Vezi pe GitHub↗

    Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

    Script for automating various memory-based analysis tasks.

    Python
    Vezi pe GitHub↗49
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Memory Forensics