Repository navigation

#

memory-forensics

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++
3277
1 天前

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C
2148
21 天前
stuxnet999/MemLabs

Educational, CTF-styled labs for individuals interested in Memory Forensics

Shell
1719
4 年前

AVML - Acquire Volatile Memory for Linux

Rust
937
2 天前

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

PowerShell
619
1 个月前

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.

Python
253
5 个月前

Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

PowerShell
237
21 天前

Allows you to quickly query a Windows machine for RAM artifacts

Python
221
5 年前

A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University

Rich Text Format
182
2 年前

Hyper-V Research is trendy now

C
178
1 年前

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Python
130
3 年前

C# Implementation of Jared Atkinson's Get-InjectedThread.ps1

C#
53
4 年前

A short and small memory forensics helper.

Python
52
8 年前

A script to assist in processing forensic RAM captures for malware triage

Shell
27
4 年前