Skip to content

Entry

Volatility

Appears in 8 awesome lists

Python based memory extraction and analysis framework.

Open github.comvolatilityfoundation/volatility

Found in these lists

Awesome-anti-forensic

Section: Analysis / Gathering tool (Know your ennemies) · Advanced memory forensics framework.

StaleScore 50

Awesome CTF

Section: Forensics · To investigate memory dumps.

StaleScore 58

awesome-game-security

Section: Anti Cheat

FreshScore 88

Awesome Incident Response

Section: Memory Analysis Tools · Advanced memory forensics framework.

ActiveScore 82

Awesome Malware Analysis

Section: Memory Forensics · Advanced memory forensics framework.

StaleScore 58

Awesome Security

Section: Forensics · Python based memory extraction and analysis framework.

SlowScore 70

Awesome Termux Hacking

Section: General · An advanced memory forensics framework.

StaleScore 47

awesome-python

Section: Reverse Engineering · An advanced memory forensics framework (archived)

FreshScore 81

Wireshark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.

In 20 listsDetails

Fibratus

Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which…

In 8 listsDetails

wazuh/wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

GRR Rapid Response

Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in…

In 6 listsDetails

bulk_extractor

Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.

In 6 listsDetails

CTRE

A Compile time PCRE (almost) compatible regular expression matcher. [MIT]

In 4 listsDetails

dvcs-ripper

Rip web accessible (distributed) version control systems: SVN/GIT/HG... by @kost.

In 4 listsDetails

a0rtega/pafish

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do (archived)

In 4 listsDetails