WindowsMemPageDelta

Memory anomaly detector

Software designed to monitor Windows executable memory page changes to detect anomalies in system behavior

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

GitHub

28 stars
6 watching
5 forks
Language: C++
last commit: about 4 years ago

Related projects:

Repository Description Stars
nccgroup/exploit_mitigations A knowledge base documenting exploit mitigations across various operating systems and software 874
nccgroup/conmachi Analyzes and reports on the security configuration of a container environment 102
rek7/mxtract Analyzes and dumps memory to extract sensitive information from running processes 582
evild3ad/memprocfs-analyzer Automated forensic analysis tool for Windows memory dumps 540
nccgroup/house A toolkit for analyzing and monitoring runtime mobile applications 1,398
antique-team/memcad Analyzes C code for its memory layout and dependencies 25
huoji120/duckmemoryscan A tool to detect memory-based evasion techniques used in malware and rootkits 702
reclassnet/reclass.net A .NET-based port of ReClass with additional features and support for various data types and memory analysis tools. 1,829
gleeda/memtriage Analyze Windows machine RAM artifacts using Winpmem and Volatility 218
perceptionpoint/suprotect Changes memory protection in an arbitrary process by modifying its mapping 46
janneman84/leakedviewcontrollerdetector Automated tool to detect and alert about memory leaks in UIKit apps 30
nccgroup/nccfsas Contains publicly released information on simulated full-spectrum attacks on file systems and security protocols. 606
velocidex/winpmem A tool for acquiring and manipulating physical memory in Windows 693
nccgroup/tracy A tool designed to help identify vulnerabilities in web applications by recording and monitoring user input and output 553
mobileforensicsresearch/mem Tool to dump memory from Android devices 66