MalConfScan Logo

MalConfScan

0
Free
Visit Website

MalConfScan is a Volatility plugin that extracts configuration data of known malware, searches for malware in memory images, and dumps configuration data. It also has a function to list strings to which malicious code refers. Supported malware families include Ursnif, Emotet, Smoke Loader, PoisonIvy, CobaltStrike, and many others. Additionally, it can dump decoded strings or DGA domains. MalConfScan also provides additional analysis by listing strings to which malicious code refers and decoding configuration data usually encoded by malware.

FEATURES

ALTERNATIVES

A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

Zenduty's platform provides real-time operational health monitoring and incident response orchestration to improve incident response times and build a solid on-call culture.

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

Forensics tool for exploring offline Docker filesystems.

A digital forensics tool that provides read-only access to file-system objects from various storage media types and file formats.

Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved