An advanced memory forensics framework
☆96Sep 26, 2019Updated 6 years ago
Alternatives and similar repositories for win10_volatility
Users that are interested in win10_volatility are comparing it to the libraries listed below
Sorting:
- Rekall Memory Forensic Framework☆33Aug 5, 2019Updated 6 years ago
- pure Python binary analysis framework☆23Oct 26, 2018Updated 7 years ago
- It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.☆23Nov 11, 2018Updated 7 years ago
- WIP python3 plugin for x64dbg☆16Mar 31, 2021Updated 4 years ago
- Registry Miner☆14Apr 10, 2018Updated 7 years ago
- FLARE Kernel Shellcode Loader☆178May 3, 2019Updated 6 years ago
- bunch of random stuff☆21Apr 11, 2020Updated 5 years ago
- Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.☆51Apr 9, 2019Updated 6 years ago
- Anything related to Ghidra☆12Apr 22, 2019Updated 6 years ago
- Code Coverage client for DynamoRIO☆12Jan 20, 2019Updated 7 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Mar 25, 2021Updated 4 years ago
- Extract annoations from Ghidra into an X32/X64 dbg database☆57Feb 24, 2021Updated 5 years ago
- ☆35Jul 20, 2021Updated 4 years ago
- Simple tool to extract icons from a pe file and other useful information☆13Jun 22, 2018Updated 7 years ago
- An AFF4 C++ implementation.☆214Mar 24, 2023Updated 2 years ago
- X-Ways Forensic/ WinHex templates☆50Jan 25, 2022Updated 4 years ago
- ☆24Aug 30, 2019Updated 6 years ago
- Page File analysis tools.☆131Dec 3, 2015Updated 10 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- My collection of scripts for Ghidra (https://github.com/NationalSecurityAgency/ghidra)☆10Sep 13, 2020Updated 5 years ago
- Attempt to replicate the functions of auto_rip by Corey Harrell in Python.☆12Aug 4, 2024Updated last year
- ☆16Apr 16, 2017Updated 8 years ago
- The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.☆13Sep 9, 2020Updated 5 years ago
- Tools for macOS Forensic Bootable media☆15May 20, 2020Updated 5 years ago
- ☆23Jun 1, 2023Updated 2 years ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- ☆432May 3, 2023Updated 2 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆196Feb 16, 2023Updated 3 years ago
- ☆136Jan 24, 2019Updated 7 years ago
- A modern Python-3-based alternative to RegRipper☆205Mar 31, 2025Updated 11 months ago
- Parser for $UsnJrnl on NTFS☆120Nov 27, 2022Updated 3 years ago
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- R-CSIRT Linux Triage tool☆39Jun 28, 2018Updated 7 years ago
- ☆29May 10, 2020Updated 5 years ago
- Bro PCAP Processing and Tagging API☆28Nov 9, 2017Updated 8 years ago
- An NTFS/FAT parser for digital forensics & incident response☆220Oct 31, 2025Updated 4 months ago
- Binee: binary emulation environment☆530Feb 25, 2023Updated 3 years ago
- Miscellaneous Scripts☆17Sep 11, 2020Updated 5 years ago
- Get intelligence info (tags, mitre techniques, yara and more) and find similar malware in a fast and easy way☆19Jun 6, 2022Updated 3 years ago