
linux_screenshot_xwindows
Volatility plugin to extract X screenshots from a memory dump

Volatility plugin to extract X screenshots from a memory dump

Automagically extract forensic timeline from volatile memory dump

Linux Memory Cryptographic Keys Extractor

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

A centralized and enhanced memory analysis platform

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Differential Analysis of Malware in Memory

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Contains tools to perform malware and forensic analysis in Memory

Educational demonstration of CVE-2023-32784 KeePass master password recovery via memory dump analysis, with step-by-step exploit setup and mitigation…

Script for automating Linux memory capture and analysis

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…