基于Memprocfs和Volatility的可视化内存取证工具
-
Updated
Jun 3, 2025 - Python
基于Memprocfs和Volatility的可视化内存取证工具
Project containing several tools/ scripts to recover the OpenSSH session keys used to encrypt/ decrypt SSH traffic.
Volatility3 Linux profiles
Volatility, on Docker 🐳
PyDFIRRam is a Python library leveraging Volatility 3 to simplify and enhance memory forensics. It streamlines the research, parsing, and analysis of memory dumps, allowing users to focus on data rather than commands.
Skalle is a handy add-on for Volatility that lets you run it in a graphical user interface. It also adds some cool features!
Generate Volatility3 profiles from BTF.
A suite of Volatility 3 plugins for memory forensics of Docker containers
Volatility 3 plugins to extract a module as complete as possible
My Linux profiles built for Volatility 2/3
Linux BPF plugins for Volatility3
Container to use the dwarf2json tool to generate Linux Profiles based on CentOS7 for Volatility3.
Linux symbols creation tool for Volatility3
GLASS (Global Language And Site Scanner) is a Volatility plugin designed by Clayton Wenzel, James Baumhardt, and Nathan Eberly, aiming to swiftly identify and classify malicious domains and unexpected languages within a memory dump, providing users with dynamic insights for forensic investigations.
PsXview plugin for volatility3 by MY7H404 - Find hidden processes with various process listings
A Volatility3 plugin to ask chatGPT
MCP (Model Context Protocol) interface for Volatility 3, providing memory forensics capabilities through LLM-based tools. Query, analyze, and automate Volatility 3 plugins using natural language via API or agent-based workflows
Docker container to run volatility3
Add a description, image, and links to the volatility3 topic page so that developers can more easily learn about it.
To associate your repository with the volatility3 topic, visit your repo's landing page and select "manage topics."