Power-Response
MemProcFS-Analyzer
Power-Response | MemProcFS-Analyzer | |
---|---|---|
2 | 2 | |
61 | 401 | |
- | - | |
0.0 | 6.1 | |
about 4 years ago | about 2 months ago | |
PowerShell | PowerShell | |
GNU General Public License v3.0 only | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Power-Response
-
Remote Computer Forensics
Power Response
- DFIR - Triage tools
MemProcFS-Analyzer
-
MemProcFS - This Changes Everything
I’ve been using this for a bit now and love it! Also please check the work done by evil3ad with MemProcFS-Analyzer. https://github.com/evild3ad/MemProcFS-Analyzer
- Volatility 3 commands and usage tips to get started with memory forensics. Volatility 3 + plugins make it easy to do advanced memory analysis.
What are some alternatives?
grr - GRR Rapid Response: remote live forensics for incident response
MemLabs - Educational, CTF-styled labs for individuals interested in Memory Forensics
sysmon-modular - A repository of sysmon configuration modules
community - Volatility plugins developed and maintained by the community
WindowsDFIR - Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or events.
Kuiper - Digital Forensics Investigation Platform
Trawler - PowerShell script to help Incident Responders discover potential adversary persistence mechanisms.
Cortex - Cortex: a Powerful Observable Analysis and Active Response Engine
Live-Forensicator - Powershell Script to aid Incidence Response and Live Forensics | Bash Script for MacOS Live Forensics and Incidence Response
community3 - Volatility3 plugins developed and maintained by the community
Collect-MemoryDump - Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR