
dfirtriage
Digital forensic acquisition tool for Windows based incident response.

Digital forensic acquisition tool for Windows based incident response.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Extract Windows credentials directly from VM memory snapshots and virtual disks

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A python script developed to process Windows memory images based on triage type.

A Windows kernel dump C++ parser library with Python 3 bindings.

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Security sensor for realtime threat detection and protection

Volatility plugin for extracts configuration data of known malware

Automagically extract forensic timeline from volatile memory dump

volatility explorer (volatility 2)

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.