
moneta
Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Advanced macOS system monitor leveraging Apple Endpoint Security to collect, enrich, and display process, file, memory, and XPC events for malware…

LD_PRELOAD shared library that hides a Linux process from tools like ps and lsof by intercepting readdir and proc filesystem calls.

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Scan files or process memory for CobaltStrike beacons and parse their configuration

some gadgets about windows process and ready to use :)

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…