Velocidex / WinPmem
The multi-platform memory acquisition tool.
☆764Updated 3 months ago
Alternatives and similar repositories for WinPmem:
Users that are interested in WinPmem are comparing it to the libraries listed below
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆592Updated last week
- Living Off The Land Drivers☆1,133Updated 2 weeks ago
- RegRipper3.0☆583Updated 3 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆568Updated this week
- ☆1,610Updated 6 months ago
- ☆2,062Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆711Updated this week
- Open Source EDR for Windows☆1,195Updated 2 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆735Updated last year
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,108Updated this week
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆704Updated last month
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,126Updated last month
- ReversingLabs YARA Rules☆799Updated this week
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆843Updated 3 years ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆582Updated last week
- ☆514Updated 5 months ago
- An Active Defense and EDR software to empower Blue Teams☆1,267Updated last year
- ☆760Updated last year
- Repository of YARA rules made by Trellix ATR Team☆579Updated this week
- Collection of private Yara rules.☆344Updated last week
- Event Tracing For Windows (ETW) Resources☆364Updated 5 months ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆577Updated 10 months ago
- ☆539Updated last year
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆516Updated 2 years ago
- Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the in…☆1,127Updated last year
- ☆1,049Updated last year
- Lnk Explorer Command line edition!!☆290Updated 2 months ago
- Parses $MFT from NTFS file systems☆228Updated this week
- ☆498Updated 3 months ago
- RDP Bitmap Cache parser☆513Updated 2 months ago