
python-haystack
Process heap analysis framework - Windows/Linux - record type inference and forensics

Process heap analysis framework - Windows/Linux - record type inference and forensics

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Log what files are accessed by any Linux process

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Scan files or process memory for CobaltStrike beacons and parse their configuration

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

A python script developed to process Windows memory images based on triage type.

Visualize the virtual address space of a Windows process on a Hilbert curve.

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…