TazWake / volatility-plugins
Learning volatility plugins.
☆19Updated 4 years ago
Alternatives and similar repositories for volatility-plugins:
Users that are interested in volatility-plugins are comparing it to the libraries listed below
- Triaging Windows event logs based on SANS Poster☆39Updated 2 years ago
- ☆34Updated 2 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 3 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- ☆15Updated 3 years ago
- Carbon Black Response IR tool☆53Updated 4 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- Manipulate timestamps on NTFS☆50Updated 10 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆38Updated last year
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 2 months ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- Tools and Binaries to use with KAPE☆12Updated 5 years ago
- ☆26Updated 3 years ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated 11 months ago
- Vagrant Files to create a Virtualbox VM for Malware Analysis☆13Updated 3 years ago
- Quick & Dirty DFIR scripts developed by Ebryx DFIR team to keep handy during field assignment☆14Updated 8 months ago
- Get intelligence info (tags, mitre techniques, yara and more) and find similar malware in a fast and easy way☆17Updated 2 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆26Updated 2 years ago
- Python based CLI for MalwareBazaar☆36Updated 4 months ago
- Modular malware analysis artifact collection and correlation framework☆53Updated 11 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- THOR MITRE ATT&CK Framework Coverage☆24Updated 4 years ago
- A project created with an aim to emulate and test exfiltration of data over different network protocols.☆31Updated 2 years ago
- ☆38Updated 3 years ago
- This repository contains zip archives of pcaps for our Wireshark tutorial about examining Emotet infection traffic. The password for any …☆24Updated 4 years ago
- Links to malware-related YARA rules☆15Updated 2 years ago
- Threat Hunt Investigation Methodology and Procedure☆15Updated 2 years ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆13Updated last year
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆26Updated 2 years ago