moneta

Memory analyzer

A tool for analyzing memory on Windows systems to detect malware IOCs

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

GitHub

707 stars
14 watching
86 forks
Language: C++
last commit: over 2 years ago
artifactdumphollowinginjectioniocmalwarememorymonetapeprocessreflectivescannershellcodeusermodewindows

Related projects:

RepositoryDescriptionStars
gleeda/memtriageAnalyze Windows machine RAM artifacts using Winpmem and Volatility218
eset/malware-iocA repository of malware indicators and rules for threat hunting and analysis.1,698
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281
crowdstrike/supermemA tool for processing Windows memory images to extract relevant information260
mkorman90/volatilitybotAutomates memory analysis of malware samples and memory dumps by extracting binaries, injections, strings, and analyzing code using heuristics and YARA/Clam AV scanners.264
antique-team/memcadAnalyzes C code for its memory layout and dependencies25
rek7/mxtractAnalyzes and dumps memory to extract sensitive information from running processes582
cristianzsh/frekiA platform for analyzing malware and performing reverse engineering on binary files424
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
guelfoweb/peframeAnalyzes Portable Executable malware and malicious MS Office documents for various suspicious features612
hasherezade/hollows_hunterAnalyzes running processes to detect and dump malicious code2,047
huoji120/duckmemoryscanA tool to detect memory-based evasion techniques used in malware and rootkits711
ytisf/muninnA tool to assist in memory forensics analysis on Windows systems by automating the process of extracting and exporting relevant data from memory images.52
googleprojectzero/bochspwn-reloadedAn emulator-based tool to detect kernel memory disclosure vulnerabilities by tracking uninitialized memory in guest operating systems.297