VolatilityBot

Memory analyzer

Automates memory analysis of malware samples and memory dumps by extracting binaries, injections, strings, and analyzing code using heuristics and YARA/Clam AV scanners.

VolatilityBot – An automated memory analyzer for malware samples and memory dumps

GitHub

264 stars
27 watching
59 forks
Language: Python
last commit: over 5 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
kevthehermit/volutilityA web-based tool for analyzing memory dumps using the Volatility framework.381
bashtage/archProvides tools and models for analyzing financial time series and detecting patterns in volatility.1,342
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281
carlospolop/autovolatilityA tool for running multiple volatility plugins simultaneously to analyze and extract data from memory dumps.110
kd8bny/limeaideAutomates the process of remotely dumping RAM and creating volatility profiles on Linux clients.161
gleeda/memtriageAnalyze Windows machine RAM artifacts using Winpmem and Volatility218
jpcertcc/malconfscanTools to extract configuration data from known malware samples in memory images.483
jameshabben/evolveA web interface for analyzing memory dumps using the Volatility framework, providing an interactive and collaborative environment for forensic analysis.259
ldo-cert/orochiA framework for collaborative memory dump analysis using Volatility and distributed processing226
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12
telekom-security/malware_analysisAn analysis repository providing scripts, signatures, and IOCs for detecting and analyzing malware.110
citronneur/volatility-wnfTools for analyzing Windows Notification Facilities and related data15
malwarecantfly/vba2graphAnalyzes VBA code to generate visual call graphs and highlights potential malicious keywords275
jnraber/virtualdeobfuscatorAnalyzes malware runtraces to remove virtual machine-based protections and extract the original binary's bytecode instructions133
mrphrazer/hitb2021ams_deobfuscationAutomated deobfuscation of malware code using symbolic execution and simplification techniques72