ics_mem_collect Logo

ics_mem_collect

0
Free
Visit Website

For many industrial control system devices, there is not a simple solution for programmatically accessing memory. Without an API, an incident responder or digital forensics analyst may be required to manually probe memory looking for anomalies or malicious activity. This project is intended to develop APIs that allow an analyst to adapt pre-existing tools or rapidly build new tools in order to target these devices. Current Devices: GE D20MX Future Work: JTAG Interface

FEATURES

ALTERNATIVES

A command-line tool for searching and extracting strings from files with various options like ASCII and Unicode string search.

Remote Acquisition Tool

Modern digital forensics and incident response platform with comprehensive tools.

MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.

A tool for discovering, analyzing, and remedying sensitive data

A bash script for automating Linux swap analysis for post-exploitation or forensics purposes.

usbdeath is an anti-forensic tool that manipulates udev rules for known USB devices and performs actions on unknown USB device insertion or specific USB device removal.

Automated tool for parsing Windows registry hives and extracting valuable information for forensic analysis.