
volatility
An advanced memory forensics framework

An advanced memory forensics framework

Collection of forensic tools

A centralized and enhanced memory analysis platform

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

Live hunting of code injection techniques

Volatility plugin for extracts configuration data of known malware

Collecting & Hunting for IOCs with gusto and style

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.