muninn

Memory analysis helper

A tool to assist in memory forensics analysis on Windows systems by automating the process of extracting and exporting relevant data from memory images.

A short and small memory forensics helper.

GitHub

52 stars
11 watching
9 forks
Language: Python
last commit: almost 9 years ago
Linked from 1 awesome list

memory-forensicspythonvolatility

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
n0fate/volafoxA memory analysis toolkit for macOS developed in Python166
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12
kevthehermit/volutilityA web-based tool for analyzing memory dumps using the Volatility framework.381
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281
mkorman90/volatilitybotAutomates memory analysis of malware samples and memory dumps by extracting binaries, injections, strings, and analyzing code using heuristics and YARA/Clam AV scanners.264
crowdstrike/supermemA tool for processing Windows memory images to extract relevant information260
wmkhoo/taintgrindA tool to track and analyze memory corruption in C programs253
chipmuenk/pyfdaA tool for designing and analyzing digital filters with a graphical user interface.658
natebrune/fmemA Linux kernel module designed to help analyze volatile memory without the limitations of traditional memory dumping tools.115
kero99/mftmactimeAnalyzes and processes NTFS file system data to extract timeline information and run YARA rules for malware detection.12
thewhiteninja/ntfstoolA forensic tool for analyzing NTFS volumes and decrypting encrypted files485
forrest-orr/monetaA tool for analyzing memory on Windows systems to detect malware IOCs707
gleeda/memtriageAnalyze Windows machine RAM artifacts using Winpmem and Volatility218
reclassnet/reclass.netA .NET-based port of ReClass with additional features and support for various data types and memory analysis tools.1,850