Skip to main content

A curated list of awesome Memory Forensics for DFIR

548
GitHub Stars
102
Curated Resources
8
Categories
17 hours ago
Last Refreshed
ToolBooksCourseVideosArticlesPapersDatasetsChallenges

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me dfir science resources from awesome-memory-forensics"

Installation instructions →

What's inside

Tool

  • AVMLMemory Acquisition

    AVML is an X86_64 userland volatile memory acquisition tool written in Rust, intended to be deployed as a static binary.

  • Digital CollectorMemory Acquisition

    A powerful forensic imaging software solution to perform triage, live data acquisition and targeted data collection for Windows and Mac computers.

  • dwarf2jsonMemory Analysis

    Go utility that processes files containing symbol and type information to generate Volatilty3 Intermediate Symbol File (ISF) JSON output suitable for Linux and macOS analysis.

  • EVTXtractMemory Acquisition

    EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.

  • FEX Memory ImagerMemory Acquisition

    FEX Memory Imager (FEX Memory) is a free imaging tool designed to capture the physical Random Access Memory (RAM) of a suspect's running computer. This allows investigators to recover and analyze valuable artifacts found only in memory.

  • fmemMemory Acquisition

    This module creates /dev/fmem device, that can be used for dumping physical memory, without limits of /dev/mem (1MB/1GB, depending on distribution).

Books

Showing a sample of 102 resources. View the full list on GitHub →