Volatility profiles for Linux and Mac OS X
☆327Oct 30, 2022Updated 3 years ago
Alternatives and similar repositories for profiles
Users that are interested in profiles are comparing it to the libraries listed below
Sorting:
- Volatility plugins developed and maintained by the community☆375Apr 5, 2021Updated 4 years ago
- An advanced memory forensics framework☆7,982May 16, 2025Updated 10 months ago
- Volatility Linux Profiles☆27Aug 1, 2014Updated 11 years ago
- Script for automating Linux memory capture and analysis☆13May 6, 2020Updated 5 years ago
- Script for automating Linux memory capture and analysis☆274Feb 1, 2020Updated 6 years ago
- Rekall Memory Forensic Framework☆1,999Oct 18, 2020Updated 5 years ago
- LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices…☆1,954Updated this week
- Plugins I've written for Volatility☆216Dec 1, 2023Updated 2 years ago
- Web App for Volatility framework☆390Jan 13, 2026Updated 2 months ago
- A collection of Volatility Framework plugins.☆26Aug 29, 2013Updated 12 years ago
- VolDiff: Malware Memory Footprint Analysis based on Volatility☆197Sep 12, 2017Updated 8 years ago
- An advanced memory forensics framework☆96Sep 26, 2019Updated 6 years ago
- Windows Thingies in Python for live use.☆24Apr 22, 2019Updated 6 years ago
- Tools for parsing Forensic images☆41Dec 14, 2018Updated 7 years ago
- Windows Live Artifacts Acquisition Script☆190Jun 20, 2022Updated 3 years ago
- Super timeline all the things☆2,034Feb 10, 2026Updated last month
- threadmap plugin for Volatility Foundation☆27Aug 23, 2021Updated 4 years ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆209Mar 12, 2025Updated last year
- Allows you to quickly query a Windows machine for RAM artifacts☆219Jul 17, 2020Updated 5 years ago
- CLBX file format☆20May 13, 2021Updated 4 years ago
- Yara intergrated into BurpSuite☆48Jun 30, 2016Updated 9 years ago
- AVML - Acquire Volatile Memory for Linux☆1,064Updated this week
- NDISPktScan is a plugin for the Volatility Framework. It parses the Ethernet packets stored by ndis.sys in Windows kernel space memory.☆12Oct 23, 2015Updated 10 years ago
- ☆82Jul 5, 2016Updated 9 years ago
- Web interface for the Volatility Memory Forensics Framework☆259Nov 21, 2017Updated 8 years ago
- ☆11Aug 3, 2018Updated 7 years ago
- Offline Active Directory Domain Services (AD DS) Join☆12Jan 4, 2017Updated 9 years ago
- Python installable command line utiltity for mitigation of host and key compromises.☆347Jul 23, 2021Updated 4 years ago
- A Python library to emit Sensu events that the Yelp Sensu Handlers can understand for Self-Service Sensu Monitoring☆14Sep 4, 2025Updated 6 months ago
- Volatility 3.0 development☆3,981Updated this week
- Lite version of PDF X-RAY that uses no backend☆38Nov 11, 2011Updated 14 years ago
- A Powershell incident response framework☆1,640Nov 22, 2022Updated 3 years ago
- Parser for Windows Scheduled Task files.☆13Apr 26, 2023Updated 2 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- Various snippets created during malware analysis☆464Oct 3, 2025Updated 5 months ago
- Loki - Simple IOC and YARA Scanner☆3,733Jan 12, 2026Updated 2 months ago
- Ansible playbook to install Malware Information Sharing Platform (MISP)☆17Feb 20, 2015Updated 11 years ago
- PowerForensics provides an all in one platform for live disk forensic analysis☆1,427Nov 16, 2023Updated 2 years ago
- NAT Pinning test suite tool for penetration testers.☆31Feb 17, 2014Updated 12 years ago