
avml
Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

The multi-platform memory acquisition tool.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Volatility plugin for extracts configuration data of known malware

Scan files or process memory for CobaltStrike beacons and parse their configuration

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

DLL Injection tool to unlock guest VMs

🐍 High-performance, multi-threaded YARA & IOC scanner

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Live hunting of code injection techniques

Windows Analysis and Research Toolkit

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Swift-based macOS incident response framework for collecting and analyzing host artifacts, including filesystem timestamps, browser data, unified…

Script for automating Linux memory capture and analysis

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

A python script developed to process Windows memory images based on triage type.