
fibratus
Security sensor for realtime threat detection and protection

Security sensor for realtime threat detection and protection

Windows tool for dumping malware PE files from memory back to disk for analysis.

A python script developed to process Windows memory images based on triage type.

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

volatility explorer (volatility 2)

Tools for the Computer Incident Response Team :computer:

Volatility Explorer Suit (volatility 3)

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

Yet Another Memory Analyzer for malware detection

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Scripts for extracting useful information from infected memory dumps

Contains tools to perform malware and forensic analysis in Memory


Code Injection, Inject malicious payload via pagetables pml4.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

An Active Defense and EDR software to empower Blue Teams

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Hunts out CobaltStrike beacons and logs operator command output