breppo / Volatility-BitLocker
Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the volume.
☆38Updated 5 years ago
Alternatives and similar repositories for Volatility-BitLocker:
Users that are interested in Volatility-BitLocker are comparing it to the libraries listed below
- Windows symbol tables for Volatility 3☆81Updated 7 months ago
- volatility explorer☆91Updated 4 years ago
- Volatility plugin to extract BitLocker Full Volume Encryption Keys (FVEK)☆65Updated 3 years ago
- RegRipper4.0☆44Updated last year
- Volatility3 plugins developed and maintained by the community☆51Updated last year
- Volatility, on Docker 🐳☆33Updated 7 months ago
- ☆18Updated 2 years ago
- A small util to brute-force prefetch hashes☆76Updated 2 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆204Updated last year
- Linpmem is a linux memory acquisition tool☆77Updated 9 months ago
- ☆56Updated 4 months ago
- Volatility Symbol Generator for Linux Kernels☆32Updated last year
- Tools that trigger False Positive AV alerts☆44Updated last month
- A collection of tools and detections for the Sliver C2 Frameworj☆116Updated last year
- Powershell Linter☆50Updated 2 weeks ago
- DPAPILAB Next Gen, script collection☆79Updated 2 years ago
- AdHoc solutions☆48Updated last year
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles☆159Updated 4 months ago
- Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers☆112Updated 5 months ago
- Retrieve inner payloads from Donut samples☆90Updated last year
- Cobalt Strike Beacon configuration extractor and parser.☆150Updated 3 years ago
- Memory mapping profiles for forensic analysis using volatility 3☆25Updated 2 years ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆249Updated last year
- Repository of Yara Rules☆100Updated this week
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆75Updated 6 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆225Updated this week
- Yara Rules for Modern Malware☆73Updated 11 months ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆59Updated 2 months ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆108Updated 3 years ago
- A collection of tools to interact with Microsoft Security Response Center API☆95Updated last year