Highlights
- Pro
Stars
Builds malware analysis Windows VMs so that you don't have to.
VolatilityBot – An automated memory analyzer for malware samples and memory dumps
A curated list of awesome malware analysis tools and resources
A curated list of tools for incident response
Web interface for the Volatility Memory Forensics Framework
Digital Forensics artifact repository
Various public documents, whitepapers and articles about APT campaigns
Tool to extract indicators of compromise from security reports in PDF format
Smart DLL execution for malware analysis in sandbox systems
FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis
A network sniffer that logs all DNS server replies for use in a passive DNS setup
Example programs used in the automating DFIR series
An advanced memory forensics framework
Web Starter Kit - a workflow for multi-device websites
Volatility profiles for Linux and Mac OS X
analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.
Alienvault Labs Projects Random Stuff
Arkime is an open source, large scale, full packet capturing, indexing, and database system.