An advanced memory forensics framework
☆96Sep 26, 2019Updated 6 years ago
Alternatives and similar repositories for win10_volatility
Users that are interested in win10_volatility are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Rekall Memory Forensic Framework☆33Aug 5, 2019Updated 6 years ago
- Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.☆51Apr 9, 2019Updated 6 years ago
- bunch of random stuff☆21Apr 11, 2020Updated 5 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Mar 25, 2021Updated 4 years ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- pure Python binary analysis framework☆23Oct 26, 2018Updated 7 years ago
- The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.☆13Sep 9, 2020Updated 5 years ago
- FLARE Kernel Shellcode Loader☆177May 3, 2019Updated 6 years ago
- It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.☆23Nov 11, 2018Updated 7 years ago
- Extract annoations from Ghidra into an X32/X64 dbg database☆57Feb 24, 2021Updated 5 years ago
- WIP python3 plugin for x64dbg☆16Mar 31, 2021Updated 4 years ago
- Page File analysis tools.☆131Dec 3, 2015Updated 10 years ago
- An AFF4 C++ implementation.☆214Mar 24, 2023Updated 3 years ago
- ☆82Jul 5, 2016Updated 9 years ago
- Registry Miner☆14Apr 10, 2018Updated 7 years ago
- X-Ways Forensic/ WinHex templates☆51Jan 25, 2022Updated 4 years ago
- A composite score for one's GitHub quality.☆22May 1, 2022Updated 3 years ago
- PyCommand Scripts for Immunity Debugger☆37Jun 21, 2014Updated 11 years ago
- ☆16Apr 16, 2017Updated 8 years ago
- A multi-threaded malware sample downloader based upon given MD-5/SHA-1/SHA-256 hashes, using multiple malware databases.☆30Apr 14, 2023Updated 2 years ago
- ☆432May 3, 2023Updated 2 years ago
- R-CSIRT Linux Triage tool☆39Jun 28, 2018Updated 7 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆196Feb 16, 2023Updated 3 years ago
- My collection of scripts for Ghidra (https://github.com/NationalSecurityAgency/ghidra)☆10Sep 13, 2020Updated 5 years ago
- ☆35Jul 20, 2021Updated 4 years ago
- Anything related to Ghidra☆12Apr 22, 2019Updated 6 years ago
- RDP Bitmap Cache parser☆640Jan 21, 2025Updated last year
- ☆15Mar 28, 2015Updated 10 years ago
- ☆23Jun 1, 2023Updated 2 years ago
- Code Coverage client for DynamoRIO☆12Jan 20, 2019Updated 7 years ago
- Attempt to replicate the functions of auto_rip by Corey Harrell in Python.☆12Aug 4, 2024Updated last year
- ☆24Aug 30, 2019Updated 6 years ago
- ☆136Jan 24, 2019Updated 7 years ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19May 11, 2021Updated 4 years ago
- Volatility plugins developed and maintained by the community☆371Apr 5, 2021Updated 4 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆36Feb 2, 2022Updated 4 years ago
- Our CTF to celebrate our hackers approaching $50M in bounty earnings!☆15Mar 25, 2023Updated 2 years ago
- Miscellaneous Scripts☆17Sep 11, 2020Updated 5 years ago