
NTDLL-Unhook
proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.

proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Yet Another Memory Analyzer for malware detection

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Scripts for extracting useful information from infected memory dumps

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Contains tools to perform malware and forensic analysis in Memory

An advanced memory forensics framework