
grr
Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Labtainers: A Docker-based cyber lab framework

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

The multi-platform memory acquisition tool.

Volatility 3 ported to Rust. Same output, much faster.

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Script for automating Linux memory capture and analysis

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

A centralized and enhanced memory analysis platform

An advanced memory forensics framework

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

UNIX-like reverse engineering framework and command-line toolset.

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.