monnappa22 / Psinfo
Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process Enivornment Block) and displays the collected information and suspicious memory regions for all the processes running on the system. This plugin should allow a security analyst to get the process related informa…
☆36Updated 8 years ago
Alternatives and similar repositories for Psinfo:
Users that are interested in Psinfo are comparing it to the libraries listed below
- Extract BITS jobs from QMGR queue and store them as CSV records☆75Updated 2 months ago
- Binary commandline executable to parse ETL files☆67Updated 6 years ago
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- Userland API monitor for threat hunting☆58Updated 5 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆117Updated 11 months ago
- TA505 unpacker Python 2.7☆47Updated 4 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- Steezy - Ghetto Yara Generation☆15Updated 2 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆86Updated 7 years ago
- PE Import Hash Generator☆79Updated 7 years ago
- Generate a Yara rule to find base64-encoded files containg a specific keyword☆40Updated 6 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Force-Directed Graph Generator for Volatility Ouputs☆26Updated 6 years ago
- hopefully a source-to-source deobfuscator, aiming at deobfuscating common scripts languages such as Powershell, VBA and Javascript. Curre…☆40Updated 5 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- Random hunting ordiented yara rules☆96Updated 2 years ago
- Evil Reflective DLL Injection Finder☆47Updated 6 years ago
- PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.☆56Updated 3 years ago
- Extract compressed memory pages from page-aligned data☆45Updated 6 years ago
- Lazy Office Analyzer☆122Updated 8 years ago
- This repository regroups the Yara Rules for the Unprotect Project☆25Updated 4 years ago
- Handy scripts to speed up malware analysis☆35Updated last year
- Miscellaneous Scripts☆17Updated 4 years ago
- Generate YARA rules for OOXML documents.☆38Updated last year
- ☆82Updated 8 years ago
- Tools and Binaries to use with KAPE☆12Updated 5 years ago
- Volatility plugins created by the author☆44Updated 9 years ago
- Python IOC Editor☆63Updated 10 years ago
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆137Updated 2 years ago