
rastrea2r
Collecting & Hunting for IOCs with gusto and style

Collecting & Hunting for IOCs with gusto and style

Automagically extract forensic timeline from volatile memory dump

Digital forensic acquisition tool for Windows based incident response.

Enumerate various traits from Windows processes as an aid to threat hunting

Volatility 3 ported to Rust. Same output, much faster.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A Windows kernel dump C++ parser library with Python 3 bindings.

Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

volatility explorer (volatility 2)

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Tools for the Computer Incident Response Team :computer:

Volatility Explorer Suit (volatility 3)

Linux kernel driver for physical memory acquisition, enabling read access to any physical address including reserved memory and memory holes, with…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.


Yet Another Memory Analyzer for malware detection

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003