JPCERTCC / Windows-Symbol-TablesLinks
Windows symbol tables for Volatility 3
β91Updated last year
Alternatives and similar repositories for Windows-Symbol-Tables
Users that are interested in Windows-Symbol-Tables are comparing it to the libraries listed below
Sorting:
- RegRipper4.0β74Updated 3 months ago
- Volatility, on Docker π³β40Updated last month
- Elastic Security Labs releasesβ81Updated last month
- YARA rule analyzer to improve rule quality and performanceβ107Updated 7 months ago
- Dump quarantined files from Windows Defenderβ67Updated 3 years ago
- JPCERT/CC public YARA rules repositoryβ110Updated last week
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIRβ251Updated 3 weeks ago
- Volatility3 plugins developed and maintained by the communityβ60Updated 2 years ago
- A guide on how to write fast and memory friendly YARA rulesβ157Updated 9 months ago
- Cobalt Strike Beacon configuration extractor and parser.β157Updated 3 weeks ago
- Collection of rules created using YARA-Signator over Malpediaβ141Updated last year
- A small util to brute-force prefetch hashesβ78Updated 3 years ago
- Volatility Symbol Generator for Linux Kernelsβ36Updated 2 years ago
- A specification and style guide for YARA rulesβ60Updated last year
- Volatility 3 Pluginsβ21Updated 3 years ago
- Parses amcache.hve files, but with a twist!β144Updated 10 months ago
- A ProcessMonitor visualization application written in rust.β184Updated 2 years ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!β82Updated 2 years ago
- LILO based Pulse Secure appliance disk image decryptorβ13Updated last year
- 100 Days of YARA to be updated with rules & ideas as the year progressesβ60Updated 2 years ago
- Volatility3 Linux profilesβ68Updated last week
- Powershell Linterβ84Updated last week
- Collection of Volatility2 profiles, generated against Linux kernels.β53Updated 3 weeks ago
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy accessβ¦β76Updated last week
- Initial triage of Windows Event logsβ103Updated last year
- Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.β143Updated 2 months ago
- β147Updated last month
- Repository of Yara Rulesβ128Updated 2 weeks ago
- Linux Evidence Acquisition Frameworkβ118Updated last year
- Rules Shared by the Community from 100 Days of YARA 2023β78Updated 2 years ago