superponible / volatility-plugins
Plugins I've written for Volatility
☆199Updated 11 months ago
Related projects ⓘ
Alternatives and complementary repositories for volatility-plugins
- RDP Bitmap Cache parser☆479Updated 11 months ago
- Beta versions of my software☆245Updated last year
- Volatility plugins developed and maintained by the community☆342Updated 3 years ago
- Volatility profiles for Linux and Mac OS X☆318Updated 2 years ago
- An advanced memory forensics framework☆92Updated 5 years ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆189Updated 4 years ago
- ☆192Updated last month
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆131Updated 2 years ago
- Keep track of the labs from the book "Practical Malware Analysis"☆167Updated 5 years ago
- Volatility Plugins☆62Updated last year
- Autoruns plugin for the Volatility framework☆118Updated 5 years ago
- An NTFS/FAT parser for digital forensics & incident response☆191Updated 2 weeks ago
- ☆294Updated 4 years ago
- Setup scripts for my Malware Analysis VMs☆245Updated 2 years ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆417Updated 3 years ago
- Smart DLL execution for malware analysis in sandbox systems☆141Updated 9 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆573Updated 6 months ago
- Wraps around various tools and provides some additional checks/information to produce a centralized report of a PE file.☆204Updated 10 years ago
- Course content and slides from my ancient training on Reverse Engineering & Malware Analysis☆142Updated 4 years ago
- Generating YARA rules based on binary code☆203Updated 3 years ago
- x86 emulation and shellcode detection☆148Updated 7 months ago
- ☆474Updated 7 years ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆241Updated last year
- Run several volatility plugins at the same time☆108Updated 2 years ago
- Exploiting challenges in Linux and Windows☆121Updated 4 years ago
- VolatilityBot – An automated memory analyzer for malware samples and memory dumps☆263Updated 3 years ago
- volatility explorer☆90Updated 4 years ago
- snake - a malware storage zoo☆217Updated last year
- Public repository for windbglib, a wrapper around pykd.pyd (for Windbg), used by mona.py☆323Updated 2 years ago
- Vulnerability examples.☆399Updated 6 months ago