C++ volatile memory artifact extractor for incident response
-
Updated
Feb 20, 2026 - C++
C++ volatile memory artifact extractor for incident response
AI-powered Volatility3 memory forensics companion with grounded triage, deterministic rules, timelines, report diffing, and DFIR chat.
Custom Volatility3 plugin for Windows Registry memory triage, persistence hunting, and baseline diff analysis.
Introducing the Temporal Dimension to Memory Forensics - ACM Transactions on Privacy and Security 2019
Historical lab prototype / archive — not a product.
Volatility profile for uclinux
Scalar Venom Attack: A critical HSM initialization vulnerability (CVE-2025-60013) enables private Bitcoin wallet key recovery through buffer overflow exploitation and shell metacharacters in the F5OS-A FIPS security module
Practical 8-phase Volatility 3 investigation playbook for DFIR, incident response, and memory forensics professionals
Advanced Android digital forensics lab for acquisition planning, anti-forensics evaluation, memory triage, evidence integrity, and research-aligned casework.
Forensic analyzer for LLM-process memory dumps: reconstruct conversations, detect credentials with validated (not entropy-only) detectors, and prove the gap teams miss — redaction at the display layer is not erasure, the secret survives in the KV-cache and retry buffers.
A lightweight, profile-free Linux memory forensics tool
Windows kernel driver that brute-forces a target process's CR3 via PFN database scan
Memory forensics analyzer — byte-level string and PE header carving, process carving, known-bad artifact detection, hashing and timeline JSON reports from RAM dumps.
SSYM 内存取证符号格式研究与验证 / Research on a compiled symbol format for memory forensics, with PDB, JSON and SSYM benchmarks and Volatility 3 comparisons. StarMem source code is not public.
Q-learning agent for Power Quest (GBC), combining reverse-engineered game memory addresses with reinforcement learning.
Vision-transformer classification of Windows process memory; published binary accuracy 99.2%.
Live PID forensics TUI for blue teams. Read-only /proc investigator for a running Linux process: files, sockets, memory, capabilities, triage findings, opt-in strace/eBPF/perf tracing and a hashed evidence case. Rust + Ratatui.
Distill — Finite state machine parsing engine for streaming extraction of structured data from unstructured text. Parses data according to specified rules and transfers it in the required format
To associate your repository with the memory-forensics topic, visit your repo's landing page and select "manage topics."