k1nd0ne / VolWeb
A centralized and enhanced memory analysis platform
☆436Updated 2 months ago
Alternatives and similar repositories for VolWeb:
Users that are interested in VolWeb are comparing it to the libraries listed below
- CLI tools for forensic investigation of Windows artifacts☆327Updated 5 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆619Updated last month
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆338Updated 8 months ago
- Incident Response collection and processing scripts with automated reporting scripts☆296Updated 9 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆559Updated last month
- Live Feed of C2 servers, tools, and botnets☆619Updated this week
- Yet another Ransomware gang tracker☆413Updated last week
- An offensive data enrichment pipeline☆670Updated last week
- sandbox approach for malware developers and red teamers to test payloads against detection mechanisms before deployment☆699Updated last month
- Rapidly Search and Hunt through Linux Forensics Artifacts☆188Updated last year
- Automated YARA Rule Standardization and Quality Assurance Tool☆207Updated this week
- This repository is a compilation of all APT simulations that target many vital sectors,both private and governmental. The simulation inc…☆637Updated 3 weeks ago
- Customizable Linux Persistence Tool for Security Research and Detection Engineering.☆607Updated last month
- a tool to help operate in EDRs' blind spots☆728Updated 4 months ago
- 🏴☠️💰 Another Ransomware gang tracker☆190Updated last week
- Ransomware simulator written in Golang☆433Updated 2 years ago
- Advanced Bash script designed for conducting digital forensics on Linux systems☆141Updated last year
- An open-source self-hosted purple team management web application.☆267Updated 3 weeks ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆709Updated 2 weeks ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆147Updated 6 months ago
- A repository of credential stealer formats☆210Updated 3 weeks ago
- An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz☆353Updated 2 weeks ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&…☆360Updated 2 years ago
- PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection…☆656Updated this week
- Simulate the behavior of AV/EDR for malware development training.☆519Updated last year
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆283Updated this week
- ☆515Updated 6 months ago
- Automatically created C2 Feeds☆600Updated this week
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,643Updated 5 months ago