MagnetForensics / dumpit-linux
Memory acquisition for Linux that makes sense.
☆184Updated last year
Alternatives and similar repositories for dumpit-linux:
Users that are interested in dumpit-linux are comparing it to the libraries listed below
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- Windows Forensics Environment Builder☆133Updated 3 months ago
- Forensics Wiki, a wiki devoted to information about digital forensics (also known as computer forensics)☆271Updated last month
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆342Updated 8 months ago
- Repository of Yara Rules☆110Updated last week
- Automated YARA Rule Standardization and Quality Assurance Tool☆210Updated this week
- The Volatility Collaborative GUI☆243Updated last week
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆60Updated 5 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆619Updated last month
- ☆127Updated 2 weeks ago
- Rules shared by the community from 100 Days of YARA 2024☆85Updated 3 months ago
- A guide on how to write fast and memory friendly YARA rules☆142Updated 2 months ago
- Windows symbol tables for Volatility 3☆83Updated 9 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆237Updated 3 weeks ago
- Signatures and IoCs from public Volexity blog posts.☆353Updated 2 months ago
- A python script developed to process Windows memory images based on triage type.☆262Updated last year
- MacOS forensic acquisition made simple☆119Updated last week
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆159Updated 4 months ago
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆109Updated 3 weeks ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆175Updated this week
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆149Updated 7 months ago
- Harness the power of Splunk for your investigations☆99Updated 3 weeks ago
- CLI tools for forensic investigation of Windows artifacts☆327Updated 5 months ago
- ☆201Updated 5 months ago
- ☆157Updated last year
- Dump quarantined files from Windows Defender☆62Updated 3 years ago
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates…☆63Updated 2 weeks ago
- $MFT directory tree reconstruction & FILE record info☆304Updated 6 months ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆141Updated last year
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆180Updated 11 months ago