tribalchicken / volatility-bitlocker
Volatility plugin to extract BitLocker Full Volume Encryption Keys (FVEK)
☆65Updated 3 years ago
Alternatives and similar repositories for volatility-bitlocker:
Users that are interested in volatility-bitlocker are comparing it to the libraries listed below
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the…☆35Updated 4 years ago
- Comae Hibernation File Decompressor☆142Updated last year
- Windows link file (shortcuts) examiner☆67Updated 7 months ago
- volatility explorer☆91Updated 4 years ago
- Windows DPAPI laboratory☆87Updated 6 years ago
- An advanced memory forensics framework☆93Updated 5 years ago
- ☆56Updated 3 months ago
- Repository containing many useful scripts☆74Updated 2 years ago
- ☆16Updated 2 years ago
- Google Chrome internals analysis using Volatility☆41Updated 2 years ago
- Psinfo is a Volatility plugin which collects the process related information from the VAD (Virtual Address Descriptor) and PEB (Process E…☆36Updated 8 years ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆37Updated 8 years ago
- DPAPI offline decryption utility☆67Updated 2 years ago
- Volatility Symbol Generator for Linux Kernels☆32Updated last year
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff☆54Updated 8 months ago
- Extract compressed memory pages from page-aligned data☆42Updated 6 years ago
- Volatility Framework plugin for extracting BitLocker FVEK (Full Volume Encryption Key)☆225Updated 8 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆74Updated 10 years ago
- hopefully a source-to-source deobfuscator, aiming at deobfuscating common scripts languages such as Powershell, VBA and Javascript. Curre…☆40Updated 5 years ago
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- ☆66Updated last year
- Manipulate timestamps on NTFS☆50Updated 10 years ago
- ☆71Updated 2 years ago
- ☆18Updated 11 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆99Updated 5 years ago
- Windows Event Log Knowledge Base☆22Updated 3 months ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆21Updated 5 years ago
- PoC for hiding data within $MFT☆12Updated 10 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆42Updated 4 years ago