Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.
☆51Apr 9, 2019Updated 6 years ago
Alternatives and similar repositories for MemoryDecompression
Users that are interested in MemoryDecompression are comparing it to the libraries listed below
Sorting:
- Windows registry samples☆24Nov 18, 2018Updated 7 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Repository for LNK stuff☆31Aug 31, 2022Updated 3 years ago
- USN to JSON☆22Apr 4, 2020Updated 5 years ago
- An advanced memory forensics framework☆96Sep 26, 2019Updated 6 years ago
- ☆16Feb 26, 2018Updated 8 years ago
- Tools for parsing Forensic images☆41Dec 14, 2018Updated 7 years ago
- ☆17Jul 26, 2018Updated 7 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆26Oct 25, 2020Updated 5 years ago
- VBA analysis tools☆25Aug 15, 2025Updated 7 months ago
- Extract compressed memory pages from page-aligned data☆47Sep 25, 2018Updated 7 years ago
- VB Exe Parser is an IDA script written in Python. This script will help you to parse VB program internal structures. It can find: Event, …☆18Oct 7, 2016Updated 9 years ago
- Page File analysis tools.☆131Dec 3, 2015Updated 10 years ago
- ☆11Aug 3, 2018Updated 7 years ago
- ☆32Feb 7, 2018Updated 8 years ago
- Yet another registry parser☆137Apr 15, 2022Updated 3 years ago
- This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD (raw), AFF disk image file without converting it, dire…☆54Oct 15, 2019Updated 6 years ago
- ☆48Jul 7, 2020Updated 5 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- Query and report user logons relations from MS Windows Security Events☆243Aug 9, 2018Updated 7 years ago
- cve-2019-0808-poc☆48Mar 25, 2019Updated 6 years ago
- super-Django-CC is a simle web interface for commoncrawl.org☆15Dec 8, 2022Updated 3 years ago
- NTFS file system specimens☆13Jul 3, 2023Updated 2 years ago
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆150May 29, 2020Updated 5 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- API functions for Malware Research☆35Jul 9, 2019Updated 6 years ago
- Python based Office Macro Generator. Also does rudamentary obfuscation.☆12Jun 6, 2016Updated 9 years ago
- Parses the WMI object database....looking for persistence☆34Dec 12, 2019Updated 6 years ago
- Zerokit/GAPZ rootkit (non buildable and only for researching)☆185Mar 30, 2019Updated 6 years ago
- Still in dev mode☆12Apr 24, 2018Updated 7 years ago
- ☆94Nov 1, 2018Updated 7 years ago
- Handy scripts to speed up malware analysis☆34Oct 3, 2023Updated 2 years ago
- Indices for courses in SANS' Network Security Operations curriculum☆17Feb 5, 2016Updated 10 years ago
- Development guide for Volatility Plugins☆22Sep 6, 2017Updated 8 years ago
- ☆12Sep 8, 2020Updated 5 years ago
- AppXSvc Arbitrary File Security Descriptor Overwrite EoP☆20Sep 15, 2019Updated 6 years ago
- Site for IWS book content☆17Oct 28, 2018Updated 7 years ago
- Takes raw hex shellcode (e.g. msfvenom hex format) from a cmd line arg, text file, or URL download and runs it.☆20Dec 17, 2018Updated 7 years ago
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago