amir9339 / volatility-docker
A suite of Volatility 3 plugins for memory forensics of Docker containers
☆17Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for volatility-docker
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆63Updated 9 months ago
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 3 weeks ago
- Small web frontend for using openAI's GPT-3.5 and GPT-4's API☆52Updated 3 months ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 2 years ago
- Reads and prints information from the website MalAPI.io☆38Updated 2 years ago
- The core backend server handling API requests and task management☆31Updated 2 weeks ago
- ☆41Updated 7 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆62Updated 2 years ago
- Pointer was developed for massive hunting and mapping Cobalt Strike servers exposed on the internet.☆65Updated 2 years ago
- TAPIR is a multi-user, client/server, incident response framework☆44Updated 2 years ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆104Updated 2 years ago
- yara detection rules for hunting with the threathunting-keywords project☆87Updated this week
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆65Updated 2 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆21Updated 2 weeks ago
- Volatility, on Docker 🐳☆29Updated 4 months ago
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆131Updated 2 years ago
- Harvest Linux forensic data for operational triage of an event.☆50Updated 5 months ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 2 years ago
- Ransomware Simulator for testing Blue Team Detections☆35Updated 2 years ago
- ☆43Updated last year
- ☆79Updated last year
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆27Updated this week
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆56Updated last week
- RegRipper4.0☆39Updated last year
- A Self-Contained Open-Source Cyberattack Experimentation Testbed☆35Updated 3 weeks ago
- YARA rule analyzer to improve rule quality and performance☆93Updated 11 months ago
- ☆15Updated 2 weeks ago
- A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.☆94Updated last year
- Triaging Windows event logs based on SANS Poster☆37Updated last year
- Automatic detection engineering technical state compliance☆50Updated 4 months ago