Velocidex / WinPmem
The multi-platform memory acquisition tool.
☆738Updated 2 months ago
Alternatives and similar repositories for WinPmem:
Users that are interested in WinPmem are comparing it to the libraries listed below
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆584Updated 2 months ago
- Living Off The Land Drivers☆1,104Updated 2 weeks ago
- RegRipper3.0☆576Updated 2 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆566Updated last week
- ☆1,591Updated 5 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆730Updated 10 months ago
- ReversingLabs YARA Rules☆791Updated 3 weeks ago
- RDP Bitmap Cache parser☆501Updated 3 weeks ago
- Dynamic unpacker based on PE-sieve☆704Updated this week
- Sophos-originated indicators-of-compromise from published reports☆564Updated last week
- ☆2,047Updated last year
- Event Tracing For Windows (ETW) Resources☆361Updated 4 months ago
- Project for tracking publicly disclosed DLL Hijacking opportunities.☆703Updated 3 weeks ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆575Updated 9 months ago
- MBC content in markdown☆405Updated last month
- The Volatility Collaborative GUI☆237Updated this week
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆698Updated last week
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,095Updated 2 months ago
- ☆514Updated 4 months ago
- Open Source EDR for Windows☆1,179Updated last year
- ☆738Updated last year
- Repository of YARA rules made by Trellix ATR Team☆576Updated last year
- ☆750Updated last year
- ☆482Updated last year
- ☆489Updated last month
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆841Updated 3 years ago
- Parses $MFT from NTFS file systems☆216Updated 3 weeks ago
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,104Updated this week
- LSASS memory dumper using direct system calls and API unhooking.☆1,508Updated 4 years ago
- A tool to kill antimalware protected processes☆1,412Updated 3 years ago