Repository navigation

#

memory-forensics

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++
3405
3 个月前

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

C
2209
3 个月前
stuxnet999/MemLabs

Educational, CTF-styled labs for individuals interested in Memory Forensics

Shell
1749
4 年前

AVML - Acquire Volatile Memory for Linux

Rust
977
19 小时前

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

PowerShell
670
1 个月前

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.

Python
255
9 个月前

Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

PowerShell
247
5 个月前

Allows you to quickly query a Windows machine for RAM artifacts

Python
220
5 年前

A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University

Rich Text Format
193
2 年前

Hyper-V Research is trendy now

C
182
1 年前

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Python
132
4 年前

C# Implementation of Jared Atkinson's Get-InjectedThread.ps1

C#
54
4 年前

A short and small memory forensics helper.

Python
52
8 年前

Generate Volatility3 profiles from BTF.

Rust
28
8 个月前