Highly useful Volatility-Malfind output parser for detecting Code/Process Injection patterns
-
Updated
May 14, 2024 - Python
Highly useful Volatility-Malfind output parser for detecting Code/Process Injection patterns
This tool takes memory image file and exports as csv input and automatically runs cross-file triage analysis to surface suspicious indicators across all major memory artifacts. It replaces the manual, plugin-by-plugin workflow with a single interactive dashboard.
Parallel Volatility 3 pipeline for large-scale ransomware memory forensics, extracting artifacts and correlating malfind, psscan, filescan, and netscan IOCs.
Add a description, image, and links to the malfind topic page so that developers can more easily learn about it.
To associate your repository with the malfind topic, visit your repo's landing page and select "manage topics."