superponible / volatility-pluginsLinks
Plugins I've written for Volatility
☆205Updated last year
Alternatives and similar repositories for volatility-plugins
Users that are interested in volatility-plugins are comparing it to the libraries listed below
Sorting:
- Volatility plugins developed and maintained by the community☆364Updated 4 years ago
- Volatility profiles for Linux and Mac OS X☆324Updated 2 years ago
- RDP Bitmap Cache parser☆540Updated 5 months ago
- An advanced memory forensics framework☆94Updated 5 years ago
- Beta versions of my software☆255Updated last week
- ☆303Updated 4 years ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆424Updated 4 years ago
- Setup scripts for my Malware Analysis VMs☆253Updated 3 years ago
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the…☆50Updated 5 years ago
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆137Updated 2 years ago
- Quickly debug shellcode extracted during malware analysis☆604Updated 2 years ago
- Autoruns plugin for the Volatility framework☆122Updated 5 years ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆195Updated 3 months ago
- An NTFS/FAT parser for digital forensics & incident response☆203Updated 7 months ago
- Volatility3 plugins developed and maintained by the community☆58Updated 2 years ago
- Run several volatility plugins at the same time☆114Updated 2 years ago
- Collection of Linux and macOS Volatility3 Intermediate Symbol Files (ISF), suitable for memory analysis 🔍☆145Updated this week
- Volatility plugin to extract BitLocker Full Volume Encryption Keys (FVEK)☆66Updated 3 years ago
- Parses amcache.hve files, but with a twist!☆136Updated 5 months ago
- Windows symbol tables for Volatility 3☆86Updated 11 months ago
- Generating YARA rules based on binary code☆212Updated 3 years ago
- Volatility Plugins☆63Updated last year
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆581Updated last year
- volatility explorer☆91Updated 4 years ago
- Volatility3 Linux profiles☆48Updated 3 weeks ago
- Web App for Volatility framework☆381Updated 6 months ago
- Repository of yara rules☆46Updated 9 years ago
- Comae Hibernation File Decompressor☆150Updated 2 years ago
- Yara Rule Analyzer and Statistics☆375Updated 2 years ago
- Code and yara rules to detect and analyze Cobalt Strike☆268Updated 4 years ago