breppo / Volatility-BitLockerLinks
Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the volume.
β52Updated 5 years ago
Alternatives and similar repositories for Volatility-BitLocker
Users that are interested in Volatility-BitLocker are comparing it to the libraries listed below
Sorting:
- Windows symbol tables for Volatility 3β91Updated last year
- Volatility, on Docker π³β40Updated this week
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performsβ¦β226Updated last year
- bitpixie Proof of Concept - Bitlocker Decryptorβ109Updated 2 months ago
- Powershell Linterβ86Updated last week
- β81Updated 3 years ago
- A collection of tools and detections for the Sliver C2 Frameworjβ132Updated 2 years ago
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy accessβ¦β76Updated last week
- RegRipper4.0β74Updated 3 months ago
- Collection of Volatility2 profiles, generated against Linux kernels.β53Updated 3 weeks ago
- Linpmem is a linux memory acquisition toolβ94Updated 5 months ago
- A ProcessMonitor visualization application written in rust.β184Updated 2 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.β223Updated 2 years ago
- Memory mapping profiles for forensic analysis using volatility 3β30Updated 3 years ago
- Volatility Symbol Generator for Linux Kernelsβ36Updated 2 years ago
- Volatility3 plugins developed and maintained by the communityβ60Updated 2 years ago
- A small util to brute-force prefetch hashesβ78Updated 3 years ago
- Collection of my volatility3 pluginsβ18Updated last year
- volatility explorerβ93Updated 5 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIRβ251Updated 3 weeks ago
- Dump quarantined files from Windows Defenderβ67Updated 3 years ago
- VBScript & VBA source-to-source deobfuscator with partial-evaluationβ80Updated last year
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.β296Updated 2 years ago
- β61Updated last year
- A collection of tools to interact with Microsoft Security Response Center APIβ108Updated last year
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profilesβ180Updated 4 months ago
- Lnk Explorer Command line edition!!β329Updated 10 months ago
- β68Updated 2 years ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files β¦β167Updated last year
- Repository of Yara Rulesβ128Updated 2 weeks ago