MemProcFS-Analyzer
Live-Forensicator
Our great sponsors
MemProcFS-Analyzer | Live-Forensicator | |
---|---|---|
2 | 1 | |
401 | 488 | |
- | - | |
6.1 | 8.5 | |
about 2 months ago | 2 months ago | |
PowerShell | JavaScript | |
GNU General Public License v3.0 only | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
MemProcFS-Analyzer
-
MemProcFS - This Changes Everything
I’ve been using this for a bit now and love it! Also please check the work done by evil3ad with MemProcFS-Analyzer. https://github.com/evild3ad/MemProcFS-Analyzer
- Volatility 3 commands and usage tips to get started with memory forensics. Volatility 3 + plugins make it easy to do advanced memory analysis.
Live-Forensicator
What are some alternatives?
MemLabs - Educational, CTF-styled labs for individuals interested in Memory Forensics
velociraptor - Digging Deeper....
community - Volatility plugins developed and maintained by the community
Invoke-Forensics - Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.
Kuiper - Digital Forensics Investigation Platform
PowerShell-Administration-Tools - Powershell scripts for automating common system administration, blue team, and digital forensics tasks
Cortex - Cortex: a Powerful Observable Analysis and Active Response Engine
Trawler - PowerShell script to help Incident Responders discover potential adversary persistence mechanisms.
community3 - Volatility3 plugins developed and maintained by the community
Collect-MemoryDump - Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR