{"id":45193,"url":"https://github.com/beyefendi/awesome-memory-forensics","name":"awesome-memory-forensics","description":"Memory forensics literature","projects_count":54,"last_synced_at":"2026-08-01T20:00:20.399Z","repository":{"id":174519840,"uuid":"649608673","full_name":"beyefendi/awesome-memory-forensics","owner":"beyefendi","description":"Memory forensics literature","archived":false,"fork":false,"pushed_at":"2024-04-05T22:01:55.000Z","size":9,"stargazers_count":3,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2026-07-13T17:03:20.240Z","etag":null,"topics":["memory-forensics"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/beyefendi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2023-06-05T08:50:48.000Z","updated_at":"2026-06-01T14:34:25.000Z","dependencies_parsed_at":null,"dependency_job_id":"85bcef0d-cb2b-41e9-8c90-f4494af7d20e","html_url":"https://github.com/beyefendi/awesome-memory-forensics","commit_stats":null,"previous_names":["beyefendi/awesome-memory-forensics"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/beyefendi/awesome-memory-forensics","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyefendi%2Fawesome-memory-forensics","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyefendi%2Fawesome-memory-forensics/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyefendi%2Fawesome-memory-forensics/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyefendi%2Fawesome-memory-forensics/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/beyefendi","download_url":"https://codeload.github.com/beyefendi/awesome-memory-forensics/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyefendi%2Fawesome-memory-forensics/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36168841,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-08-01T02:00:05.789Z","response_time":100,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-01-13T21:19:05.166Z","updated_at":"2026-08-01T20:00:20.400Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Analysis Tools","Analysis Methods","Papers","CTFs","Courses","Volatility plugins","Frameworks"],"sub_categories":[],"readme":"# Memory Forensics Literature\n\n## Frameworks\n\n- [volatility3](https://github.com/volatilityfoundation/volatility3)\n- [MemProcFS](https://github.com/ufrisk/MemProcFS)\n\n## Volatility plugins\n\n- [**Community plugins**](https://github.com/volatilityfoundation/community/)\n- [**Plugin development tutorial**](https://github.com/iAbadia/Volatility-Plugin-Tutorial)\n- [Prefetch](https://github.com/forensicxlab/volatility3_plugins)\n- [AnyDesk](https://github.com/forensicxlab/volatility3_plugins)\n- [KeePass](https://github.com/forensicxlab/volatility3_plugins)\n- [USBSTOR](https://github.com/kevthehermit/volatility_plugins)\n- [LastPass](https://github.com/kevthehermit/volatility_plugins)\n- [CobaltStrike](https://github.com/kevthehermit/volatility_plugins)\n- [Uninstallinfo](https://github.com/superponible/volatility-plugins)\n- [Prefetch](https://github.com/superponible/volatility-plugins)\n- [idxparser](https://github.com/superponible/volatility-plugins)\n- [Firefox History](https://github.com/superponible/volatility-plugins)\n- [Chrome History](https://github.com/superponible/volatility-plugins)\n- [sqlite](https://github.com/superponible/volatility-plugins)\n- [Trustrecords](https://github.com/superponible/volatility-plugins)\n- [ssdeepscan](https://github.com/superponible/volatility-plugins)\n- [malfinddeep](https://github.com/superponible/volatility-plugins)\n- [apihooksdeep](https://github.com/superponible/volatility-plugins)\n- [RAMSCAN](https://github.com/TazWake/volatility-plugins)\n- [CMDCHECK](https://github.com/TazWake/volatility-plugins)\n- [Fast VAD Scan](https://github.com/TazWake/volatility-plugins)\n- [Path Check](https://github.com/TazWake/volatility-plugins)\n- [Triagecheck](https://github.com/TazWake/volatility-plugins)\n- [AutoRuns](https://github.com/tomchop/volatility-autoruns)\n- [Bitlocker](https://github.com/tribalchicken/volatility-bitlocker)\n- [Linux - Inodes](https://github.com/forensicxlab/volatility3_plugins)\n\n## MemProcFS extensions\n\n- [MemProcFS-Analyzer](https://github.com/evild3ad/MemProcFS-Analyzer)\n\n## Analysis Tools\n\n- [VolWeb -  Volatility 3 frontend](https://github.com/k1nd0ne/VolWeb)\n- [Orochi - The Volatility Collaborative GUI](https://github.com/LDO-CERT/orochi)\n- [Volatility Workbench](https://www.osforensics.com/tools/volatility-workbench.html)\n- [memOptix - Jupyter notebook](https://github.com/blueteam0ps/memOptix)\n- [Auto_vol - Automated basics volatility tasks](https://github.com/Zeecka/Auto_vol) - Extracts bitlocker/luks keys and mounts disk image\n- [AutoVolatility](https://github.com/carlospolop/autoVolatility)\n- [VolatilityBot](https://github.com/mkorman90/VolatilityBot)\n- [Calamity](https://github.com/Hestat/calamity)\n- [memtriage](https://github.com/gleeda/memtriage)\n- [AutoTimeliner](https://github.com/andreafortuna/autotimeliner)\n\n## Analysis Methods\n\n- [Power Up Memory Forensics with Memory Baseliner](https://www.sans.org/blog/power-up-memory-forensics-with-memory-baseliner/)\n- [Automating Memory Analysis with AChoirX, Volatility, and LOKI](http://www.musectech.com/2022/04/automating-memory-analysis-with-achoirx.html)\n- [VMware Memory Analysis with MemProcFS](https://blog.ecapuano.com/p/vmware-memory-analysis-with-memprocfs)\n- [Comae Memory and Network Analysis: Beginning an Incident Investigation](https://www.magnetforensics.com/blog/comae-memory-and-network-analysis-beginning-an-incident-investigation/)\n\n## Analysis of Artifacts\n\n- [Volatility3: Modern Windows Hibernation file analysis](https://www.forensicxlab.com/posts/hibernation/)\n\n## Papers\n\n- [2019 - Characteristics and detectability of Windows auto-start extensibility points in memory forensics](https://www.sciencedirect.com/science/article/pii/S1742287619300362)\n- [2018 - Deepmem: Learning graph neural network models for fast and robust memory forensic analysis](https://dl.acm.org/doi/pdf/10.1145/3243734.3243813)\n- [2018 - Experimental analysis of web browser sessions using live forensics method](https://faiz.dosen.ittelkom-pwt.ac.id/wp-content/uploads/sites/79/2018/11/Experimental-Analysis-of-Web-Browser-Sessions-Using-Live-Forensics-Method-fix.pdf)\n- [2017 - Web browser forensics: google chrome](https://www.researchgate.net/profile/Digvijaysinh-Rathod-2/publication/321534636_WEB_BROWSER_FORENSICS_GOOGLE_CHROME/links/5a26cd99aca2727dd8839621/WEB-BROWSER-FORENSICS-GOOGLE-CHROME.pdf)\n- [2017 - Scanning memory with Yara](https://www.sciencedirect.com/science/article/pii/S1742287617300592)\n\n\n## Courses\n\n- [Digital Forensics Lab \u0026 Shared Cyber Forensic Intelligence Repository](https://github.com/frankwxu/digital-forensics-lab)\n- [Digital Forensics Course Texas Tech University](https://github.com/asiamina/A-Course-on-Digital-Forensics)\n\n## CTFs\n\n- [Anomalies in Windows Memory](https://blog.cyber5w.com/anomalies-hunting-in-windows-memory-dump)\n- [A memory dump](https://github.com/SecurityNik/CTF) | [Write Up](https://www.securitynik.com/2024/03/total-recall-2024-memory-forensics-self.html)\n- [MemLabs - 7 challenge](https://github.com/stuxnet999/MemLabs)\n\n## Memory image dataset\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/beyefendi%2Fawesome-memory-forensics/projects"}