bridgeythegeek / ndispktscanLinks
NDISPktScan is a plugin for the Volatility Framework. It parses the Ethernet packets stored by ndis.sys in Windows kernel space memory.
☆12Updated 9 years ago
Alternatives and similar repositories for ndispktscan
Users that are interested in ndispktscan are comparing it to the libraries listed below
Sorting:
- Plugins for the Viper Framework☆14Updated 5 years ago
- Toolkit to detected abnormal activities on a Windows machine.☆11Updated 9 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Forensics triage tool relying on Volatility and Foremost☆26Updated last year
- A collection of Volatility Framework plugins.☆27Updated 11 years ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Updated 8 years ago
- a collection of yara rules for binary analysis☆24Updated 7 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆41Updated 6 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 7 years ago
- Spam Honeypot with Intelligent Virtual Analyzer☆9Updated 9 years ago
- Basic file metadata gathering script☆21Updated 3 months ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Script to parse Process Monitor XML log file, and give you a summary report.☆23Updated 9 years ago
- Working through Practical Malware Analysis from No Starch Press☆13Updated 8 years ago
- radare2 script to help on COM objects reverse engineering☆11Updated 8 years ago
- FastIR Agent is a Windows service to execute FastIR Collector on demand☆14Updated 8 years ago
- IDA Pro plugin that rename functions on load, based on functionality☆19Updated 7 years ago
- Parses Java Cache IDX files☆39Updated 7 years ago
- Print the strings of encoded printable characters in files☆12Updated 10 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Updated 4 years ago
- ☆36Updated 5 years ago
- Generate MAEC XML from Ero Carrera's pefile output☆15Updated 8 years ago
- Metasploit modules, powershell scripts and custom exploit to perform local privilege escalation on windows systems.☆11Updated 8 years ago
- Indicators of compromise relating to our report on APT10's targeting of global MSPs☆10Updated 7 years ago
- This is a python version of samesame repo to generate homograph strings☆23Updated 6 years ago
- Extracts indicators of compromise (IOCs), including domain names, IPv4 addresses, email addresses, and hashes, from text.☆13Updated 7 years ago
- EditBox is a plugin for the Volatility Framework. It extracts the text from Windows Edit controls, that is, textboxes as generated by Win…☆24Updated 8 years ago
- smtp-user-enum.pl ported into a recon-ng module.☆9Updated 11 years ago
- A Maltego transform for VirusTotal Submitter Information☆35Updated 6 years ago
- Event Log Analysis Tools☆29Updated 8 years ago