Comae Hibernation File Decompressor
☆161Apr 1, 2023Updated 3 years ago
Alternatives and similar repositories for Hibr2Bin
Users that are interested in Hibr2Bin are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Portable utility to check if a machine has been infected by Shamoon2☆15Jan 13, 2017Updated 9 years ago
- POC for IAT Parsing Payloads☆48Jan 1, 2017Updated 9 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Incident Response & Digital Forensics Debugging Extension☆399Dec 11, 2018Updated 7 years ago
- Web interface for the Volatility Memory Forensics Framework☆259Nov 21, 2017Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆345Jun 25, 2022Updated 4 years ago
- modify binary Portable Executable to hook its export functions☆68Jan 13, 2019Updated 7 years ago
- Lazy Office Analyzer☆122Feb 15, 2017Updated 9 years ago
- Site for IWS book content☆17Oct 28, 2018Updated 7 years ago
- VolDiff: Malware Memory Footprint Analysis based on Volatility☆195Sep 12, 2017Updated 8 years ago
- Web App for Volatility framework☆387Jan 13, 2026Updated 6 months ago
- Reconstruct process trees from event logs☆148Aug 12, 2020Updated 5 years ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆211Mar 12, 2025Updated last year
- Term concordances for each course in the SANS DFIR curriculum. Used for automated index generation.☆70Aug 7, 2020Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- VolatilityBot – An automated memory analyzer for malware samples and memory dumps☆268Jun 15, 2021Updated 5 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55May 18, 2019Updated 7 years ago
- An AFF4 C++ implementation.☆221Mar 24, 2023Updated 3 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆212Sep 15, 2021Updated 4 years ago
- BONOMEN - Hunt for Malware Critical Process Impersonation☆50Nov 30, 2020Updated 5 years ago
- Using WinDBG to tap into JavaScript and help with deobfuscation and browser exploit detection☆81Mar 22, 2017Updated 9 years ago
- Quickly find references to the specified Immediate number, or find the function call of specifies offset, and generate C++ functions call…☆25Feb 25, 2017Updated 9 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆59Jul 2, 2023Updated 3 years ago
- Wrapper class for IDAPython. Regroups various useful functions for reverse engineering of binaries.☆17Mar 17, 2016Updated 10 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆532Jul 6, 2026Updated 2 weeks ago
- ☆279Apr 6, 2023Updated 3 years ago
- Development guide for Volatility Plugins☆22Sep 6, 2017Updated 8 years ago
- ☆12Apr 13, 2017Updated 9 years ago
- Differential Analysis of Malware in Memory☆215Apr 16, 2017Updated 9 years ago
- Tool suite for inspecting NTFS artifacts.☆227Nov 1, 2023Updated 2 years ago
- ATrace is a tool for tracing execution of binaries on Windows.☆243Nov 19, 2025Updated 8 months ago
- Volatility plugin to extract BitLocker Full Volume Encryption Keys (FVEK)☆71Sep 20, 2021Updated 4 years ago
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆386Jun 25, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆143Apr 21, 2017Updated 9 years ago
- $I30 INDX Carver☆18Jun 23, 2025Updated last year
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆129May 3, 2026Updated 2 months ago
- Autoruns plugin for the Volatility framework☆124Jul 18, 2019Updated 7 years ago
- My collection of scripts for Ghidra (https://github.com/NationalSecurityAgency/ghidra)☆11Sep 13, 2020Updated 5 years ago
- ☆30May 23, 2017Updated 9 years ago
- Example programs used in the automating DFIR series☆63Mar 4, 2019Updated 7 years ago