基于Memprocfs和Volatility的可视化内存取证工具
-
Updated
Aug 10, 2026 - TypeScript
基于Memprocfs和Volatility的可视化内存取证工具
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
First open-source DMA-based HWID spoofer written in Rust. Spoof hardware IDs via direct memory access.
DMA-based memory analysis framework
Lightweight C++ library for external mouse control via DMA. Simple API, no configuration needed. For game development, automation, and research.
DMA-based DLL injector using MemProcFS/Hyper-V to map and execute payloads inside a guest VM process entirely from the host — no guest kernel interaction.
A tool for converting Windows PDB files used by MemProcfs to Volatility3 symbol files (.json.xz).
DMA Lab - Hardware-level anti-cheat research, firmware configs, FPGA guides and PCILeech resources
AI-assisted digital forensics lab — 12 tools, 3 runtimes, cross-source correlation, one-command automation
Modern C++17 wrapper for MemProcFS/VMMDLL with structured DMA memory APIs, process introspection, scanning, input support, and hardware-free tests.
Blue Team memory forensics investigation using Volatility 3 and MemProcFS to analyze suspicious processes, injected memory, PE modifications, network artifacts, and IOCs through evidence-driven forensic analysis.
Live physical memory acquisition for Windows with byte-accurate error isolation, live kernel hints, and zero vendor lock-in.
Add a description, image, and links to the memprocfs topic page so that developers can more easily learn about it.
To associate your repository with the memprocfs topic, visit your repo's landing page and select "manage topics."