volatilityfoundation / dwarf2jsonLinks
convert ELF/DWARF symbol and type information into vol3's intermediate JSON
☆122Updated 8 months ago
Alternatives and similar repositories for dwarf2json
Users that are interested in dwarf2json are comparing it to the libraries listed below
Sorting:
- Linpmem is a linux memory acquisition tool☆84Updated last year
- Windows symbol tables for Volatility 3☆86Updated 11 months ago
- Volatility3 plugins developed and maintained by the community☆58Updated 2 years ago
- An NTFS/FAT parser for digital forensics & incident response☆203Updated 7 months ago
- Generate Volatility3 profiles from BTF.☆24Updated 6 months ago
- Memory acquisition for Linux that makes sense.☆198Updated last year
- capemon: CAPE's monitor☆122Updated last week
- The Linux port of the Sysinternals Sysmon tool.☆263Updated 3 months ago
- ☆102Updated 2 years ago
- Volatility Symbol Generator for Linux Kernels☆35Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆64Updated last month
- Volatility, on Docker 🐳☆34Updated 2 months ago
- A guide on how to write fast and memory friendly YARA rules☆144Updated 4 months ago
- Elastic Security Labs releases☆68Updated this week
- Use YARA rules on Time Travel Debugging traces☆91Updated last year
- ☆106Updated last year
- Alternative YARA scanning engine☆70Updated 2 years ago
- Community modules for CAPE Sandbox☆100Updated last week
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access…☆62Updated this week
- Volatility plugin to retrieve the Full Volume Encryption Key in memory. The FVEK can then be used with the help of Dislocker to mount the…☆50Updated 5 years ago
- Red Canary's eBPF Sensor☆107Updated last week
- Golang Parser for Microsoft Event Logs☆102Updated 5 months ago
- Visually inspect and force decode YARA and regex matches found in both binary and text data. With Colors.☆128Updated 6 months ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆224Updated last week
- Parsing of YARA rules into AST and building new rulesets in C++.☆124Updated last month
- Automatically generate AV byte signatures from sets of similar binaries.☆273Updated 6 months ago
- Malduck is your ducky companion in malware analysis journeys☆337Updated last month
- Symbol hash for ELF files☆111Updated 3 years ago
- volatility explorer☆91Updated 4 years ago
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆249Updated 2 years ago