awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ufrisk avatar

ufrisk/MemProcFS

0
View on GitHub↗
4,202 星标·515 分支·C·AGPL-3.0·3 次浏览

MemProcFS

MemProcFS 是一个易失性内存分析工具和跨平台内存获取系统。它作为一个内存取证虚拟文件系统,将物理内存和内核对象映射到虚拟目录结构中,允许用户使用标准文件系统工具分析系统工件。

该项目通过提供用于内存取证的虚拟文件系统脱颖而出,能够将物理内存作为只读文件和文件夹进行浏览和查询。它还结合了基于 Yara 的内存扫描器,以识别物理内存中的恶意软件签名和注入代码。

该引擎涵盖了广泛的取证功能,包括进程和线程检查、网络连接列表和 Windows 注册表分析。它支持从实时系统、崩溃转储和虚拟机中摄取数据,同时提供符号解析以将原始内存地址转换为有意义的名称。

集成通过多语言程序化接口和针对 C 和 Java 的原生库包装器,以及用于自动化工作流的无头 Python 脚本提供支持。

Features

  • Memory Analysis - Implements a comprehensive engine for acquiring and analyzing volatile system memory and static memory dumps.
  • Memory Forensics - Analyzes physical memory dumps or live system state to identify security threats and recover system artifacts.
  • Volatile Memory Acquisition Tools - Provides a cross-platform system for capturing volatile memory from live systems, virtual machines, and remote agents.
  • Debug Symbol Resolvers - Downloads and caches symbols from remote servers to translate raw memory addresses into meaningful function names.
  • YARA Rule Execution - Identifies malicious patterns in process and kernel virtual address spaces using compiled or source YARA rule sets.
  • Virtual File Systems - Maps physical memory and kernel artifacts into a virtual directory structure for analysis via standard file system tools.
  • Forensic Memory Virtualization - Exposes physical memory and kernel objects as a virtualized directory structure of read-only files and folders.
  • Forensic Agent Communication - Minimizes network bandwidth by transmitting only file system access requests to remote analysis agents.
  • Memory Dump Parsers - Parses memory dump files across various CPU architectures to enable deep forensic analysis.
  • Remote Memory Filesystems - Acquires remote physical memory and presents it as a local virtual filesystem for exploration.
  • Physical and Virtual Memory Operations - Performs direct read and write operations on physical and virtual memory for specific processes or system-wide.
  • Thread Inspection - Exposes thread-specific data including kernel structures and stacks as files within a virtual directory.
  • Volatile Memory Ingestion - Ingests memory data from raw dump files, crash dumps, live captures, or hardware interfaces for analysis.
  • Binary Pattern Searching - Scans memory for specific binary patterns or signatures using regular expressions and YARA rules.
  • Hardware Memory Acquisition Tools - Captures volatile RAM via drivers, virtual machines, hardware interfaces, or remote agents for real-time incident response.
  • Memory Malware Analysis - Scans system memory for malicious patterns and injected code using tools like Yara rules.
  • Process Enumeration - Identifies running software by retrieving a collection of active processes from the targeted memory source.
  • Remote Memory Analysis - Analyzes memory on remote machines and optimizes network bandwidth by transmitting only specific file system access requests.
  • YARA-Based Scanning - Uses compiled Yara rules to scan physical and virtual address spaces for malicious signatures and injected code.
  • Process Metadata Inspection - Retrieves detailed process lists, module bases, function addresses, and memory maps including heaps and page table entries.
  • DNS Cache Recovery - Extracts DNS records cached by the operating system and presents them as searchable text files.
  • Headless Forensic Scripting - Executes automated Python scripts at startup to perform forensics without mounting a virtual file system.
  • Multi-Language Plugin Frameworks - Supports custom forensic capabilities through a modular system allowing extensions written in multiple programming languages.
  • Memory Analysis APIs - Offers a multi-language programmatic interface to read physical and virtual process memory without mounting a file system.
  • Kernel Object Reconstruction - Recovers file objects from the kernel pool and process handles to present a reconstructed file system.
  • DMA Memory Acquisition - Provides capabilities to acquire system memory by bypassing the CPU via hardware interfaces such as PCIe DMA.
  • Forensic Memory Mapping - Maps physical memory and system artifacts into a virtual file system for analysis with standard tools.
  • Virtual Address Translators - Translates guest physical addresses to host physical or virtual addresses within a virtual machine environment.
  • Page File Integration - Incorporates disk-based page files into the memory analysis engine to recover data swapped out of physical RAM.
  • Guest-to-Host Address Translation - Translates guest physical addresses to host virtual addresses to enable memory analysis within hypervisor-based virtual machines.
  • Programmatic Memory Interfaces - Integrates memory analysis capabilities into custom applications using native libraries or multi-language interfaces.
  • Guest-to-Host Address Translation - Extracts and translates guest memory from hypervisors to analyze the state of virtualized operating systems.
  • Memory Dump Visualizers - Exposes physical memory as a virtual file system to analyze memory dumps or live memory.
  • Guest Memory Parsing - Extracts the memory of hypervisor-based virtual machines and presents them as separate file systems for analysis.
  • Virtual Machine Detection - Identifies supported virtual machines in memory and mounts them as separate file systems or memory views.
  • Windows Registry Interfaces - Enumerates registry hives and provides interfaces to read or write their memory space for configuration analysis.
  • Memory-Based File Recovery - Extracts files from memory by locating process file handles and copying the associated data.
  • Evasion Technique Detection - Identifies evasion techniques like process hollowing by flagging discrepancies between process structures and image addresses.
  • Incident Response Triage - Connects to remote hosts or virtual machines to rapidly acquire and analyze volatile memory during investigations.
  • Injected Module Detection - Locates executable modules in private virtual address descriptors to identify hidden malware.
  • Memory Event Log Extraction - Exposes event logs found in physical memory as read-only files for use with external log viewers.
  • Process Callstack Analysis - Analyzes runtime callstacks of user-mode threads to identify function call traces using symbol resolution.
  • User-Mode Malware Detection - Scans physical memory for indicators of malicious activity like code injection and presents results as files.
  • Modular Plugin Architectures - Adds custom forensic capabilities through a modular architecture that supports multiple programming languages for extensions.
  • Active Connection Monitors - Displays active TCP connections, including addresses and associated process names, as a text file.
  • System Information Summaries - Provides a high-level overview of the kernel, operating system, and active users via a read-only text file.
  • Memory Forensics - Accesses physical memory as a virtual file system.
  • Digital Forensics - Tool for accessing physical memory as a virtual file system.
  • Memory Analysis Tools - Virtual file system for viewing physical memory as files.
  • Memory Forensics - Virtual file system for accessing physical memory.

Star 历史

ufrisk/memprocfs 的 Star 历史图表ufrisk/memprocfs 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

MemProcFS 的开源替代方案

相似的开源项目,按与 MemProcFS 的功能重合度排序。
  • ufrisk/pcileechufrisk 的头像

    ufrisk/pcileech

    7,738在 GitHub 上查看↗

    pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and conducting remote volatile memory forensics. It functions as a hardware memory acquisition tool and a PCIe DMA attack framework designed to read and write remote system memory via direct hardware interfaces. The project provides capabilities for capturing and displaying raw transaction layer packets from the PCIe bus and mounting live RAM as local drives for analysis. It enables the modification of system memory signatures and the execution of shellcode or implants within the kernel wi

    C
    在 GitHub 上查看↗7,738
  • volatilityfoundation/volatility3volatilityfoundation 的头像

    volatilityfoundation/volatility3

    4,192在 GitHub 上查看↗

    Volatility3 is a memory forensics framework and analysis tool used to parse volatile memory dumps. It extracts digital artifacts and reconstructs the runtime state of a system to recover process information, network artifacts, and other forensic evidence. The system functions as a plugin-based forensic engine and an operating system symbol resolver. It maps raw memory addresses to known system structures using symbol tables and translation layers, and provides an extensible architecture for creating custom scanners and renderers. The framework includes a command-line memory explorer for real

    Python
    在 GitHub 上查看↗4,192
  • velocidex/velociraptorVelocidex 的头像

    Velocidex/velociraptor

    3,769在 GitHub 上查看↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    在 GitHub 上查看↗3,769
  • neo23x0/lokiNeo23x0 的头像

    Neo23x0/Loki

    3,763在 GitHub 上查看↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    在 GitHub 上查看↗3,763
查看 MemProcFS 的所有 30 个替代方案→

常见问题解答

ufrisk/memprocfs 是做什么的?

MemProcFS 是一个易失性内存分析工具和跨平台内存获取系统。它作为一个内存取证虚拟文件系统,将物理内存和内核对象映射到虚拟目录结构中,允许用户使用标准文件系统工具分析系统工件。

ufrisk/memprocfs 的主要功能有哪些?

ufrisk/memprocfs 的主要功能包括:Memory Analysis, Memory Forensics, Volatile Memory Acquisition Tools, Debug Symbol Resolvers, YARA Rule Execution, Virtual File Systems, Forensic Memory Virtualization, Forensic Agent Communication。

ufrisk/memprocfs 有哪些开源替代品?

ufrisk/memprocfs 的开源替代品包括: ufrisk/pcileech — pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and… volatilityfoundation/volatility3 — Volatility3 is a memory forensics framework and analysis tool used to parse volatile memory dumps. It extracts digital… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a… volatilityfoundation/volatility — Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from… dotnet/diagnostics — The diagnostics project provides a cross-platform diagnostic infrastructure and command-line toolkit for monitoring…