memtriage

RAM analyzer

Analyze Windows machine RAM artifacts using Winpmem and Volatility

Allows you to quickly query a Windows machine for RAM artifacts

GitHub

218 stars
16 watching
22 forks
Language: Python
last commit: about 6 years ago
live-analysismalwarememorymemory-analysismemory-forensicsramvolatilitywindows-machinewinpmem

Related projects:

RepositoryDescriptionStars
mkorman90/volatilitybotAutomates memory analysis of malware samples and memory dumps by extracting binaries, injections, strings, and analyzing code using heuristics and YARA/Clam AV scanners.264
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
crowdstrike/supermemA tool for processing Windows memory images to extract relevant information260
forrest-orr/monetaA tool for analyzing memory on Windows systems to detect malware IOCs707
kd8bny/limeaideAutomates the process of remotely dumping RAM and creating volatility profiles on Linux clients.161
idiom/pftriageTool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.77
maoni0/mem-docA resource for .NET memory analysis and diagnostics1,841
antique-team/memcadAnalyzes C code for its memory layout and dependencies25
bashtage/archProvides tools and models for analyzing financial time series and detecting patterns in volatility.1,342
microsoft/mm-reactAn AI-powered system that leverages multimodal reasoning and action to analyze visual data and provide insights940
moaistory/winsearchdbanalyzerAn analyzer tool designed to parse and extract data from Windows.edb files, a database used by Windows Search.121
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281
kevthehermit/volutilityA web-based tool for analyzing memory dumps using the Volatility framework.381
mitre/advmlthreatmatrixA framework to help security analysts understand and prepare for adversarial machine learning attacks on AI systems1,056
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12