awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 个仓库

Awesome GitHub RepositoriesMemory Forensics

Tools for dissecting malware in memory images or running systems.

Explore 14 awesome GitHub repositories matching part of an awesome list · Memory Forensics. Refine with filters or upvote what's useful.

Awesome Memory Forensics GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • zardus/ctf-toolszardus 的头像

    zardus/ctf-tools

    9,434在 GitHub 上查看↗

    This project is a security tool installation framework and binary analysis toolkit designed to automate the deployment of research utilities. It provides a containerized security research environment and a system for managing Python and Ruby virtual environments to prevent dependency conflicts on the host machine. The framework distinguishes itself through a structured tool catalog and provisioning scripts that automate the installation of utilities into isolated directories. It utilizes executable symlink mapping to provide a unified command interface and supports the bootstrapping of consis

    Automates the installation and configuration of specialized frameworks for analyzing system memory dumps.

    Shell
    在 GitHub 上查看↗9,434
  • volatilityfoundation/volatilityvolatilityfoundation 的头像

    volatilityfoundation/volatility

    7,971在 GitHub 上查看↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Standard framework for memory forensic investigations.

    Pythonmalwarememorypython
    在 GitHub 上查看↗7,971
  • ufrisk/memprocfsufrisk 的头像

    ufrisk/MemProcFS

    4,202在 GitHub 上查看↗

    MemProcFS 是一个易失性内存分析工具和跨平台内存获取系统。它作为一个内存取证虚拟文件系统,将物理内存和内核对象映射到虚拟目录结构中,允许用户使用标准文件系统工具分析系统工件。 该项目通过提供用于内存取证的虚拟文件系统脱颖而出,能够将物理内存作为只读文件和文件夹进行浏览和查询。它还结合了基于 Yara 的内存扫描器,以识别物理内存中的恶意软件签名和注入代码。 该引擎涵盖了广泛的取证功能,包括进程和线程检查、网络连接列表和 Windows 注册表分析。它支持从实时系统、崩溃转储和虚拟机中摄取数据,同时提供符号解析以将原始内存地址转换为有意义的名称。 集成通过多语言程序化接口和针对 C 和 Java 的原生库包装器,以及用于自动化工作流的无头 Python 脚本提供支持。

    Virtual file system for accessing physical memory.

    C
    在 GitHub 上查看↗4,202
  • google/rekallgoogle 的头像

    google/rekall

    1,998在 GitHub 上查看↗

    Rekall Memory Forensic Framework

    Framework for advanced memory forensic analysis.

    Python
    在 GitHub 上查看↗1,998
  • denandz/keefarcedenandz 的头像

    denandz/KeeFarce

    1,021在 GitHub 上查看↗

    Extracts passwords from a KeePass 2.x database, directly from memory.

    Tool for extracting passwords from memory.

    C++
    在 GitHub 上查看↗1,021
  • swwwolf/wdbgarkswwwolf 的头像

    swwwolf/wdbgark

    642在 GitHub 上查看↗

    WinDBG Anti-RootKit Extension

    Anti-rootkit extension for the windows debugger.

    C++
    在 GitHub 上查看↗642
  • kevthehermit/volutilitykevthehermit 的头像

    kevthehermit/VolUtility

    387在 GitHub 上查看↗

    Web App for Volatility framework

    Web-based interface for the memory forensic framework.

    Python
    在 GitHub 上查看↗387
  • shanek2/invtero.netShaneK2 的头像

    ShaneK2/inVtero.net

    296在 GitHub 上查看↗

    inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

    High-speed memory analysis framework for Windows x64.

    C#
    在 GitHub 上查看↗296
  • ldo-cert/orochiLDO-CERT 的头像

    LDO-CERT/orochi

    269在 GitHub 上查看↗

    The Volatility Collaborative GUI

    Collaborative framework for forensic memory dump analysis.

    JavaScript
    在 GitHub 上查看↗269
  • jameshabben/evolveJamesHabben 的头像

    JamesHabben/evolve

    259在 GitHub 上查看↗

    Web interface for the Volatility Memory Forensics Framework

    Web interface for the volatility memory forensics framework.

    JavaScript
    在 GitHub 上查看↗259
  • 504ensicslabs/damm504ensicsLabs 的头像

    504ensicsLabs/DAMM

    214在 GitHub 上查看↗

    Differential Analysis of Malware in Memory

    Differential analysis of malware in memory using volatility.

    Python
    在 GitHub 上查看↗214
  • aim4r/voldiffaim4r 的头像

    aim4r/VolDiff

    195在 GitHub 上查看↗

    VolDiff: Malware Memory Footprint Analysis based on Volatility

    Compares memory images before and after malware execution.

    Python
    在 GitHub 上查看↗195
  • ytisf/muninnytisf 的头像

    ytisf/muninn

    52在 GitHub 上查看↗

    A short and small memory forensics helper.

    Automates volatility analysis and generates readable reports.

    Python
    在 GitHub 上查看↗52
  • sketchymoose/totalrecallsketchymoose 的头像

    sketchymoose/TotalRecall

    49在 GitHub 上查看↗

    Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

    Script for automating various memory-based analysis tasks.

    Python
    在 GitHub 上查看↗49
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Memory Forensics