MemProcFS-Analyzer
Memory analyzer
Automated tool for forensic analysis of Windows memory dumps
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
555 stars
22 watching
59 forks
Language: PowerShell
last commit: 3 months ago dfirdigital-forensicsincident-responselive-responsememory-forensicsmemprocfspowershell
Related projects:
Repository | Description | Stars |
---|---|---|
| Automates evidence collection and analysis from Windows machines using PowerShell. | 149 |
| Analyzes C code for its memory layout and dependencies | 25 |
| Analyze Windows machine RAM artifacts using Winpmem and Volatility | 218 |
| An educational platform for learning memory forensics through interactive CTF-style challenges | 1,670 |
| Tools for analyzing PPLFault-related malware behavior on Windows 10 | 134 |
| A tool to assist in memory forensics analysis on Windows systems by automating the process of extracting and exporting relevant data from memory images. | 52 |
| Analyzes and processes NTFS file system data to extract timeline information and run YARA rules for malware detection. | 12 |
| A C#-based framework for analyzing and investigating hard drive forensic data | 1,389 |
| A digital forensics tool for analyzing macOS and iOS systems | 790 |
| A digital forensics tool for parsing and analyzing NTFS/FAT file systems. | 196 |
| A PowerShell module for collecting logs and forensics data from VMware vSphere environments. | 143 |
| Tools for detecting suspicious files and directories on Windows and Linux endpoints. | 234 |
| A suite of tools and images for building and managing digital forensics environments on AWS | 494 |
| A tool for measuring and analyzing the performance of Ember.js applications. | 73 |
| Software designed to monitor Windows executable memory page changes to detect anomalies in system behavior | 28 |