google / rekall
Rekall Memory Forensic Framework
☆1,925Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for rekall
- Binary analysis and management framework☆1,539Updated last year
- LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices…☆1,727Updated last month
- FakeNet-NG - Next Generation Dynamic Network Analysis Tool☆1,806Updated this week
- GRR Rapid Response: remote live forensics for incident response☆4,785Updated this week
- FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.☆3,276Updated this week
- Super timeline all the things☆1,736Updated last month
- Noriben - Portable, Simple, Malware Analysis Sandbox☆1,121Updated 11 months ago
- Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU☆1,655Updated 9 months ago
- The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file s…☆2,632Updated this week
- Indicators of Compromises (IOC) of our various investigations☆1,655Updated this week
- Builds malware analysis Windows VMs so that you don't have to.☆1,031Updated 3 years ago
- An advanced memory forensics framework☆7,361Updated last year
- Distributed & real time digital forensics at the speed of the cloud☆1,206Updated 5 years ago
- Malcom - Malware Communications Analyzer☆1,155Updated 6 years ago
- Digital Forensics artifact repository☆1,062Updated 3 months ago
- DRAKVUF Black-box Binary Analysis☆1,064Updated this week
- CRITs - Collaborative Research Into Threats☆893Updated 5 years ago
- Volatility plugins developed and maintained by the community☆342Updated 3 years ago
- A static analyzer for PE executables.☆1,018Updated 10 months ago
- Documentation for the GRR Rapid Reponse framework☆301Updated 2 months ago
- Volatility profiles for Linux and Mac OS X☆319Updated 2 years ago
- pefile is a Python module to read and work with PE (Portable Executable) files☆1,879Updated 2 months ago
- FAME Automates Malware Evaluation☆862Updated this week
- yarGen is a generator for YARA rules☆1,558Updated 5 months ago
- Kaspersky's GReAT KLara☆697Updated 3 months ago
- Platform for Architecture-Neutral Dynamic Analysis☆2,493Updated 2 weeks ago
- Python low-interaction honeyclient☆994Updated this week
- Collaborative forensic timeline analysis☆2,615Updated 2 weeks ago
- Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, Ex…☆1,573Updated last year
- Official repository for Pyew.☆383Updated 5 years ago