MemLabs Logo

MemLabs

0
Free
Visit Website

MemLabs is an educational, introductory set of CTF-styled challenges aimed at encouraging students, security researchers, and CTF players to start with Memory Forensics. The main goal of creating this repository is to provide a reliable platform for individuals to learn, practice, and enhance their skills in memory forensics through CTF-style challenges. The structure of the repository includes different levels of difficulty challenges from Beginner's Luck to The Reckoning, each designed to help users understand how to approach CTF challenges and use volatility effectively.

FEATURES

ALTERNATIVES

mac_apt is a versatile DFIR tool for processing Mac and iOS images, offering extensive artifact extraction capabilities and cross-platform support.

Powerful tool for searching and hunting through Windows forensic artefacts with support for Sigma detection rules and custom Chainsaw detection rules.

Collects and organizes Linux OS data for detailed analysis and incident response.

A digital investigation platform for parsing, searching, and visualizing evidences with advanced analytics capabilities.

NBD is a userland implementation of the Network Block Device protocol, allowing for remote access to block devices over a network.

GVfs is a userspace virtual filesystem implementation for GIO with various backends and features.

WinSearchDBAnalyzer can parse and recover records in Windows.edb, providing detailed insights into various data types.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

PINNED