JPCERTCC / Windows-Symbol-Tables
Windows symbol tables for Volatility 3
☆81Updated 8 months ago
Alternatives and similar repositories for Windows-Symbol-Tables:
Users that are interested in Windows-Symbol-Tables are comparing it to the libraries listed below
- Collection of Volatility2 profiles, generated against Linux kernels.☆35Updated 2 weeks ago
- Volatility3 plugins developed and maintained by the community☆51Updated 2 years ago
- Use YARA rules on Time Travel Debugging traces☆89Updated last year
- Volatility, on Docker 🐳☆33Updated 8 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Volatility Symbol Generator for Linux Kernels☆33Updated last year
- volatility explorer☆91Updated 4 years ago
- A small util to brute-force prefetch hashes☆76Updated 2 years ago
- RegRipper4.0☆48Updated last year
- Cobalt Strike Beacon configuration extractor and parser.☆150Updated 3 years ago
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles☆161Updated 5 months ago
- A collection of tools and detections for the Sliver C2 Frameworj☆116Updated last year
- Repository of Yara Rules☆103Updated last month
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆30Updated 3 years ago
- Elastic Security Labs releases☆59Updated 4 months ago
- YARA rule analyzer to improve rule quality and performance☆97Updated 2 months ago
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆102Updated 2 weeks ago
- JPCERT/CC public YARA rules repository☆106Updated 3 months ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- Yara Rules for Modern Malware☆73Updated last year
- A guide on how to write fast and memory friendly YARA rules☆141Updated last month
- Linpmem is a linux memory acquisition tool☆78Updated 10 months ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆165Updated 2 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆234Updated last week
- Active C&C Detector☆152Updated last year
- Powershell Linter☆50Updated this week
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the…☆41Updated 5 years ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- ☆18Updated 2 years ago
- Dump quarantined files from Windows Defender☆61Updated 2 years ago