MagnetForensics / dumpit-linux
Memory acquisition for Linux that makes sense.
☆191Updated last year
Alternatives and similar repositories for dumpit-linux
Users that are interested in dumpit-linux are comparing it to the libraries listed below
Sorting:
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆623Updated 2 months ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- Windows symbol tables for Volatility 3☆85Updated 10 months ago
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆349Updated 9 months ago
- The Volatility Collaborative GUI☆242Updated this week
- Automated YARA Rule Standardization and Quality Assurance Tool☆218Updated this week
- A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts☆61Updated 6 months ago
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆118Updated this week
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆196Updated this week
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆177Updated this week
- ☆130Updated last week
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆239Updated last month
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆99Updated last year
- Windows Forensics Environment Builder☆135Updated 4 months ago
- ☆159Updated last year
- A centralized and enhanced memory analysis platform☆459Updated 3 months ago
- LOKI2 - Simple IOC and YARA Scanner☆93Updated 9 months ago
- Repository of Yara Rules☆110Updated last month
- Search Index Database Reporter☆109Updated 6 months ago
- ☆201Updated 6 months ago
- Parses $MFT from NTFS file systems☆238Updated last week
- A python script developed to process Windows memory images based on triage type.☆262Updated last year
- Python tool to check rootkits in Windows kernel☆195Updated 2 months ago
- Dump quarantined files from Windows Defender☆63Updated 3 years ago
- Rules shared by the community from 100 Days of YARA 2024☆85Updated 4 months ago
- Harness the power of Splunk for your investigations☆105Updated this week
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆149Updated 7 months ago
- Linpmem is a linux memory acquisition tool☆83Updated last year
- Collection of private Yara rules.☆354Updated 3 weeks ago
- CLI tools for forensic investigation of Windows artifacts☆327Updated 6 months ago