MalConfScan Logo

MalConfScan

0
Free
Visit Website

MalConfScan is a Volatility plugin that extracts configuration data of known malware, searches for malware in memory images, and dumps configuration data. It also has a function to list strings to which malicious code refers. Supported malware families include Ursnif, Emotet, Smoke Loader, PoisonIvy, CobaltStrike, and many others. Additionally, it can dump decoded strings or DGA domains. MalConfScan also provides additional analysis by listing strings to which malicious code refers and decoding configuration data usually encoded by malware.

FEATURES

ALTERNATIVES

A framework for orchestrating forensic collection, processing, and data export.

Windows event log fast forensics timeline generator and threat hunting tool.

A binary analysis platform for analyzing binary programs

A Python tool for in-depth PDF analysis and modification.

A tool with advanced filtering capabilities for analyzing events based on time, path, weekday, and date.

A free, open source collection of tools for forensic artifact and image analysis.

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

Autopsy is a GUI-based digital forensics platform for analyzing hard drives and smart phones, with a plug-in architecture for custom modules.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved