Live-Forensicator
MemProcFS-Analyzer
Live-Forensicator | MemProcFS-Analyzer | |
---|---|---|
1 | 2 | |
489 | 402 | |
- | - | |
8.5 | 6.1 | |
3 months ago | 2 months ago | |
JavaScript | PowerShell | |
- | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Live-Forensicator
MemProcFS-Analyzer
-
MemProcFS - This Changes Everything
I’ve been using this for a bit now and love it! Also please check the work done by evil3ad with MemProcFS-Analyzer. https://github.com/evild3ad/MemProcFS-Analyzer
- Volatility 3 commands and usage tips to get started with memory forensics. Volatility 3 + plugins make it easy to do advanced memory analysis.
What are some alternatives?
velociraptor - Digging Deeper....
MemLabs - Educational, CTF-styled labs for individuals interested in Memory Forensics
Invoke-Forensics - Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.
community - Volatility plugins developed and maintained by the community
PowerShell-Administration-Tools - Powershell scripts for automating common system administration, blue team, and digital forensics tasks
Kuiper - Digital Forensics Investigation Platform
Trawler - PowerShell script to help Incident Responders discover potential adversary persistence mechanisms.
Cortex - Cortex: a Powerful Observable Analysis and Active Response Engine
community3 - Volatility3 plugins developed and maintained by the community
Collect-MemoryDump - Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR