Volatility memory forensics plugin for extracting Windows DNS Cache
☆29Mar 13, 2017Updated 8 years ago
Alternatives and similar repositories for dnscache
Users that are interested in dnscache are comparing it to the libraries listed below
Sorting:
- Auxiliary scripts for Incident Response with ELK☆11Oct 7, 2015Updated 10 years ago
- Volatility plugins☆12Feb 19, 2015Updated 11 years ago
- ☆12Jun 29, 2021Updated 4 years ago
- Backdoor detection for VMware view☆13Jan 5, 2022Updated 4 years ago
- A simple and universal .NET proxy remover☆11Jun 14, 2020Updated 5 years ago
- Network Forensics Workshop Files☆17Apr 21, 2015Updated 10 years ago
- PowerShell Utilities for Security Situational Awareness☆13Jan 10, 2017Updated 9 years ago
- Volatility plugin to help identify DoublePulsar implant by listing the array of pointers SrvTransaction2DispatchTable from the srv.sys dr…☆16Aug 14, 2017Updated 8 years ago
- Proof-of-concept automated baremetal malware analysis framework.☆14Sep 24, 2015Updated 10 years ago
- Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".☆14Jul 12, 2021Updated 4 years ago
- Create an incident response triage toolkit for use with Windows or Linux.☆18Jun 14, 2020Updated 5 years ago
- DeepToad is a library and a tool to clusterize similar files using fuzzy hashing☆20Apr 5, 2020Updated 5 years ago
- Generates YARA rules to detect malware using API hashing☆17Mar 16, 2021Updated 4 years ago
- Low-level MS Windows registry files analysis tools☆19May 5, 2016Updated 9 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆40Dec 14, 2018Updated 7 years ago
- Scripts and Modules for forensical analyses of mysql database systems☆22Sep 19, 2014Updated 11 years ago
- Malware analysis tool☆22Apr 27, 2025Updated 10 months ago
- Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process E…☆39Sep 24, 2016Updated 9 years ago
- Autoruns plugin for the Volatility framework☆122Jul 18, 2019Updated 6 years ago
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Nov 13, 2022Updated 3 years ago
- Various snippets created during malware analysis☆22Apr 29, 2018Updated 7 years ago
- ☆18Apr 4, 2019Updated 6 years ago
- Parses Java Cache IDX files☆40Feb 28, 2018Updated 8 years ago
- ☆82Jul 5, 2016Updated 9 years ago
- collection of links related to using and improving windbg☆20Jun 17, 2018Updated 7 years ago
- This repo generally for malware Researcher ("Password: infected")☆19Feb 24, 2026Updated last week
- Threat Box Assessment Tool☆19Aug 15, 2021Updated 4 years ago
- Batch scripts to capture volatile and log information from a target system☆21Oct 9, 2014Updated 11 years ago
- random python stuff☆26Jan 7, 2016Updated 10 years ago
- Set of tools and documentation for leveraging private APNs for mobile network traffic analysis☆28Sep 2, 2024Updated last year
- PCILeech HP iLO4 Service☆24Jan 9, 2019Updated 7 years ago
- Collection of scripts used to analyse malware or emails☆20Oct 6, 2020Updated 5 years ago
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 6 years ago
- Experiments on C/C++ Exploits☆22Jun 30, 2020Updated 5 years ago
- A series of GPO templates☆21Jan 2, 2017Updated 9 years ago
- Code and Slides of my BSides London 2019 presentation about Attacker Emulation using CALDERA☆22Jun 9, 2019Updated 6 years ago
- Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.…☆29Jul 31, 2021Updated 4 years ago
- Decrypt NTDS hashes☆23Jan 22, 2014Updated 12 years ago
- Queries to parse sysmon event log file with microsoft logparser☆58Mar 31, 2015Updated 10 years ago