aelth / dementia-forensics
Proof of concept memory anti-forensic toolkit designed for hiding various artifacts inside the memory dump during memory acquisition on Microsoft Windows operating system
☆10Updated 5 years ago
Alternatives and similar repositories for dementia-forensics:
Users that are interested in dementia-forensics are comparing it to the libraries listed below
- ☆22Updated 3 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 2 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- ☆31Updated 4 years ago
- A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface☆13Updated 5 years ago
- ☆16Updated 4 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 4 months ago
- Antivirus Emulator Fingerprints☆27Updated 6 years ago
- ☆18Updated 3 years ago
- Windows x64 Process Scanner to detect application compatability shims☆36Updated 6 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆33Updated 3 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- Notepad++ Syntax Highlighting for Languages Used by Cyber Security Professionals☆14Updated 4 years ago
- A small library helping to parse commandline parameters (for C/C++)☆54Updated last year
- ☆24Updated 5 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆26Updated 6 years ago
- Rekall Memory Forensic Framework☆30Updated 5 years ago
- findLoop - find possible encryption/decryption or compression/decompression code☆26Updated 5 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆51Updated 2 years ago
- Kernel mode windows NT API logger☆22Updated 5 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 4 years ago
- Blog posts☆30Updated 4 years ago
- Tool to decrypt the configuration of NanoCore and dump all used plugins☆11Updated 4 years ago
- Self-Loading Registration Free COM Functions☆11Updated 5 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- ☆26Updated 3 months ago
- Reflective DLL Injection style process infector☆20Updated 6 years ago
- ☆33Updated 7 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆15Updated 3 years ago