microsoft / avml
AVML - Acquire Volatile Memory for Linux
☆925Updated this week
Alternatives and similar repositories for avml:
Users that are interested in avml are comparing it to the libraries listed below
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆569Updated last week
- Indicators of Compromises (IOC) of our various investigations☆1,745Updated last week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆731Updated 2 weeks ago
- ReversingLabs YARA Rules☆804Updated this week
- RegRipper3.0☆586Updated 3 months ago
- The multi-platform memory acquisition tool.☆766Updated 4 months ago
- yarGen is a generator for YARA rules☆1,621Updated 9 months ago
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,111Updated last week
- Sysmon for Linux☆1,842Updated last week
- YARA signature and IOC database for my scanners and tools☆2,582Updated this week
- High Octane Triage Analysis☆716Updated last week
- Digital Forensics artifact repository☆1,094Updated 3 months ago
- A rewrite of YARA in Rust.☆727Updated last week
- Rekall Memory Forensic Framework☆1,945Updated 4 years ago
- Distributed malware processing framework based on Python, Redis and S3.☆404Updated this week
- Super timeline all the things☆1,809Updated 3 weeks ago
- LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices…☆1,794Updated 5 months ago
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆707Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆583Updated last week
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆968Updated 3 weeks ago
- Noriben - Portable, Simple, Malware Analysis Sandbox☆1,143Updated last year
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆917Updated last week
- MBC content in markdown☆421Updated 2 months ago
- The Python interface for YARA☆683Updated 2 weeks ago
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,131Updated last month
- Windows Events Attack Samples☆2,326Updated 2 years ago
- Elastic Security detection content for Endpoint☆1,142Updated this week
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆471Updated 5 months ago
- An Active Defense and EDR software to empower Blue Teams☆1,268Updated last year
- FakeNet-NG - Next Generation Dynamic Network Analysis Tool☆1,878Updated 2 months ago