JPCERTCC / Windows-Symbol-TablesLinks
Windows symbol tables for Volatility 3
β91Updated last year
Alternatives and similar repositories for Windows-Symbol-Tables
Users that are interested in Windows-Symbol-Tables are comparing it to the libraries listed below
Sorting:
- RegRipper4.0β74Updated 2 weeks ago
- Volatility, on Docker π³β40Updated 3 weeks ago
- Volatility3 plugins developed and maintained by the communityβ60Updated 2 years ago
- Volatility Symbol Generator for Linux Kernelsβ35Updated 2 years ago
- A small util to brute-force prefetch hashesβ77Updated 3 years ago
- JPCERT/CC public YARA rules repositoryβ110Updated 3 weeks ago
- Elastic Security Labs releasesβ81Updated 2 weeks ago
- YARA rule analyzer to improve rule quality and performanceβ107Updated 8 months ago
- Dump quarantined files from Windows Defenderβ74Updated 3 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIRβ251Updated last month
- A collection of tools and detections for the Sliver C2 Frameworjβ133Updated 2 years ago
- Cobalt Strike Beacon configuration extractor and parser.β157Updated last month
- Parses amcache.hve files, but with a twist!β144Updated 10 months ago
- Linux Evidence Acquisition Frameworkβ117Updated last year
- Collection of Volatility2 profiles, generated against Linux kernels.β53Updated last month
- A guide on how to write fast and memory friendly YARA rulesβ157Updated 10 months ago
- Open Dataset of Cobalt Strike Beacon metadata (2018-2022)β129Updated 3 years ago
- LILO based Pulse Secure appliance disk image decryptorβ13Updated last year
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profilesβ180Updated 5 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progressesβ60Updated 2 years ago
- A C# based tool for analysing malicious OneNote documentsβ118Updated 2 years ago
- Volatility3 Linux profilesβ68Updated last month
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy accessβ¦β77Updated this week
- yara detection rules for hunting with the threathunting-keywords projectβ155Updated 7 months ago
- Initial triage of Windows Event logsβ104Updated last year
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.β301Updated 2 years ago
- Collection of rules created using YARA-Signator over Malpediaβ139Updated last year
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount theβ¦β53Updated 5 years ago
- Lazarus analysis tools and research reportβ57Updated last year
- Powershell Linterβ86Updated 3 weeks ago