Volatility plugins created by the author
☆44Oct 2, 2015Updated 10 years ago
Alternatives and similar repositories for volatility_plugins
Users that are interested in volatility_plugins are comparing it to the libraries listed below
Sorting:
- threadmap plugin for Volatility Foundation☆27Aug 23, 2021Updated 4 years ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- ☆12Dec 14, 2016Updated 9 years ago
- Parser for $LogFile on NTFS☆215Jun 1, 2025Updated 9 months ago
- ☆16Apr 16, 2017Updated 8 years ago
- misc scripts☆35Oct 23, 2018Updated 7 years ago
- A Powershell script for frequency analysis of separated values data files.☆17Jan 22, 2014Updated 12 years ago
- VolDiff: Malware Memory Footprint Analysis based on Volatility☆197Sep 12, 2017Updated 8 years ago
- Generate a histogram of TCP and UDP payload bytes from a pcap file☆24Aug 1, 2022Updated 3 years ago
- ☆82Jul 5, 2016Updated 9 years ago
- a-ray-grass is a yara module that provides support for DCSO-format bloom filters in yara. In the context of hashlookup, it allows quickly…☆14Aug 19, 2022Updated 3 years ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated 8 months ago
- Trace ScriptBlock execution for powershell v2☆40Jan 14, 2020Updated 6 years ago
- ☆16Jan 31, 2015Updated 11 years ago
- Python IOC Editor☆65Mar 10, 2015Updated 11 years ago
- A list of IOCs applicable to PoshC2☆24Aug 3, 2020Updated 5 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆209Sep 15, 2021Updated 4 years ago
- This is a hash parser that will export a rc file compatible with Metasploit. This is useful when compromising a separate domain and want …☆23Oct 8, 2014Updated 11 years ago
- Super timeline all the things☆2,034Feb 10, 2026Updated last month
- A Powershell incident response framework☆1,640Nov 22, 2022Updated 3 years ago
- A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.☆40Feb 19, 2026Updated last month
- CrowdStrike Threat Intelligence☆35Jan 14, 2023Updated 3 years ago
- Exploit kit analyzer☆22Mar 3, 2015Updated 11 years ago
- Yara rules☆22Mar 27, 2023Updated 2 years ago
- runsc loads 32/64 bit shellcode (depending on how runsc is compiled) in a way that makes it easy to load in a debugger. This code is base…☆38Dec 12, 2022Updated 3 years ago
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Oct 12, 2018Updated 7 years ago
- ☆432May 3, 2023Updated 2 years ago
- Active Directory forensic framework☆334Mar 24, 2022Updated 3 years ago
- Security Onion Splunk App☆10May 18, 2015Updated 10 years ago
- Proxy wired iOS internet connection and only allow cert server communication for safe agent signing☆13Aug 3, 2023Updated 2 years ago
- Web App for Volatility framework☆390Jan 13, 2026Updated 2 months ago
- Why hunt when you can seine?☆21May 12, 2015Updated 10 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆129Jan 12, 2025Updated last year
- ☆24Mar 13, 2026Updated last week
- Differential Analysis of Malware in Memory☆216Apr 16, 2017Updated 8 years ago
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆114Dec 20, 2025Updated 3 months ago
- Parses $MFT from NTFS file systems☆304Feb 16, 2026Updated last month
- RDP Bitmap Cache parser☆638Jan 21, 2025Updated last year
- IOC-EDT is an open source web based tool for creating indicators of compromise in the OpenIOC (http://www.openioc.org) format.☆18May 10, 2014Updated 11 years ago