How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Volatility plugin for extracts configuration data of known malware
The main features of jpcertcc/malconfscan are: Development And Analysis Tools, Memory Analysis Tools.
Open-source alternatives to jpcertcc/malconfscan include: 504ensicslabs/lime — LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and… abhinavbom/clara — Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets. aim4r/voldiff — VolDiff: Malware Memory Footprint Analysis based on Volatility. airbnb/binaryalert — BinaryAlert: Serverless, Real-time & Retroactive Malware Detection. airbus-cert/dnyara — A multi-platform .Net wrapper library for the native Yara library. 3c7/yaramanager — Simple yara rule manager.
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisitio
Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets