MalConfScan Logo

MalConfScan

0
Free
Visit Website

MalConfScan is a Volatility plugin that extracts configuration data of known malware, searches for malware in memory images, and dumps configuration data. It also has a function to list strings to which malicious code refers. Supported malware families include Ursnif, Emotet, Smoke Loader, PoisonIvy, CobaltStrike, and many others. Additionally, it can dump decoded strings or DGA domains. MalConfScan also provides additional analysis by listing strings to which malicious code refers and decoding configuration data usually encoded by malware.

FEATURES

ALTERNATIVES

A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container, aiding in digital forensic triage.

A collection of tools for extracting and analyzing information from .git repositories

Advanced computer forensics software with efficient features.

A Kernel fuzzer focusing on race bugs

Automated collection tool for incident response triage in Windows systems.

Open source tool for generating YARA rules about installed software from a running OS.

Remote Acquisition Tool

Modern digital forensics and incident response platform with comprehensive tools.