microsoft / avml
AVML - Acquire Volatile Memory for Linux
☆936Updated this week
Alternatives and similar repositories for avml:
Users that are interested in avml are comparing it to the libraries listed below
- A rewrite of YARA in Rust.☆738Updated last week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆741Updated last month
- ReversingLabs YARA Rules☆814Updated last week
- RegRipper3.0☆595Updated 4 months ago
- The multi-platform memory acquisition tool.☆775Updated 4 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆574Updated 3 weeks ago
- Sysmon for Linux☆1,866Updated 3 weeks ago
- Repository of YARA rules made by Trellix ATR Team☆592Updated last month
- yarGen is a generator for YARA rules☆1,626Updated last week
- Digital Forensics artifact repository☆1,101Updated 3 months ago
- Indicators of Compromises (IOC) of our various investigations☆1,754Updated 3 weeks ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆715Updated last week
- Distributed malware processing framework based on Python, Redis and S3.☆415Updated 3 weeks ago
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,119Updated this week
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆947Updated last week
- Super timeline all the things☆1,825Updated last month
- Rekall Memory Forensic Framework☆1,947Updated 4 years ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,108Updated 3 weeks ago
- A VBA parser and emulation engine to analyze malicious macros.☆1,085Updated 9 months ago
- Windows Events Attack Samples☆2,340Updated 2 years ago
- Sophos-originated indicators-of-compromise from published reports☆577Updated 2 weeks ago
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆977Updated 2 weeks ago
- Open Source EDR for Windows☆1,210Updated 2 years ago
- Open Source Security Events Metadata (OSSEM)☆1,261Updated 2 years ago
- Volatility plugins developed and maintained by the community☆359Updated 4 years ago
- An Active Defense and EDR software to empower Blue Teams☆1,271Updated last year
- The Volatility Collaborative GUI☆243Updated this week
- A set of Zeek scripts to detect ATT&CK techniques.☆585Updated 9 months ago
- High Octane Triage Analysis☆723Updated this week
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆706Updated 2 years ago