DuckMemoryScan

Memory scanner

A tool to detect memory-based evasion techniques used in malware and rootkits

检测绝大部分所谓的内存免杀马

GitHub

711 stars
17 watching
137 forks
Language: C++
last commit: about 4 years ago

Related projects:

RepositoryDescriptionStars
huoji120/cobaltstrikedetectedDetects potential Cobalt Strike malware by analyzing memory allocation patterns during code execution272
rek7/mxtractAnalyzes and dumps memory to extract sensitive information from running processes582
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12
trainr3kt/memreader_bofA tool that searches and extracts specific strings from another process's memory41
mirage/conanRe-implementation of a file recognition engine with support for multiple MIME types and decision trees.48
zer0mem0ry/kernelreadwritememoryA proof-of-concept project demonstrating kernel-level memory manipulation on Windows NT274
marcosd4h/memhunterAutomated endpoint sensor tool to detect memory-resident malware without requiring memory dumps378
codecat/clawsearchA plugin that scans memory in 64-bit debuggers to locate specific values, inspired by Cheat Engine.275
jpcertcc/malconfscanTools to extract configuration data from known malware samples in memory images.483
ramortegui/clamxirA wrapper around ClamAV's scanning functionality for Elixir applications.13
crowdstrike/supermemA tool for processing Windows memory images to extract relevant information260
maoni0/mem-docA resource for .NET memory analysis and diagnostics1,841
mitrecnd/malchiveA collection of reusable scripts and tools for analyzing malicious software75
zu1k/beacon_hook_bypass_memscanBypassing memory scanning to evade detection by the Karbenz CASB (Content Awareness Security Platform) security solution24
nccgroup/windowsmempagedeltaSoftware designed to monitor Windows executable memory page changes to detect anomalies in system behavior28