
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Collection of forensic tools

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

List of Awesome CobaltStrike Resources

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

A centralized and enhanced memory analysis platform

Enumerate various traits from Windows processes as an aid to threat hunting

Frida-based tool that ports Cheat Engine's MonoDataCollector to Android and iOS, enabling runtime Mono/IL2CPP data collection and memory inspection…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Volatility plugin for extracts configuration data of known malware

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Live hunting of code injection techniques

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…