tribalchicken / volatility-bitlocker
Volatility plugin to extract BitLocker Full Volume Encryption Keys (FVEK)
☆62Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for volatility-bitlocker
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the…☆35Updated 4 years ago
- Comae Hibernation File Decompressor☆141Updated last year
- An advanced memory forensics framework☆92Updated 5 years ago
- volatility explorer☆90Updated 4 years ago
- Windows link file (shortcuts) examiner☆67Updated 5 months ago
- ☆55Updated last month
- ☆66Updated last year
- Extract compressed memory pages from page-aligned data☆41Updated 6 years ago
- Windows DPAPI laboratory☆86Updated 6 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆41Updated 3 years ago
- Python implementation of LZNT1 compression/decompression☆61Updated 4 years ago
- A git history of Windows filesystems☆76Updated 4 years ago
- Volatility Framework plugin for extracting BitLocker FVEK (Full Volume Encryption Key)☆222Updated 8 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆99Updated 5 years ago
- Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process E…☆36Updated 8 years ago
- A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service), allowing arbitrary program execution as th…☆98Updated 5 years ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 5 years ago
- A boot record parser that identifies known good signatures for MBR, VBR and IPL.☆97Updated 6 years ago
- ☆14Updated 2 years ago
- Volatility3 plugins developed and maintained by the community☆45Updated last year
- hopefully a source-to-source deobfuscator, aiming at deobfuscating common scripts languages such as Powershell, VBA and Javascript. Curre…☆40Updated 5 years ago
- The Damn Vulnerable Router Firmware Project☆30Updated 6 years ago
- Google Chrome internals analysis using Volatility☆41Updated 2 years ago
- Windows symbol tables for Volatility 3☆73Updated 4 months ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago
- ☆57Updated 3 years ago
- Parser for $UsnJrnl on NTFS☆108Updated last year
- Carves and recreates VSS catalog and store from Windows disk image.☆96Updated last year
- Malware Configuration And Payload Extraction☆18Updated 4 years ago
- An NTFS/FAT parser for digital forensics & incident response☆191Updated 2 weeks ago