Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
-
Updated
Oct 29, 2025 - PowerShell
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
A comprehensive repository for CyberOps documentation, Blue Team playbooks, and open-source forensic tools like Cerberus and Chimera.
Live physical memory acquisition for Windows with byte-accurate error isolation, live kernel hints, and zero vendor lock-in.
Modular, agent-less forensic triage framework for rapid Windows & Linux artifact collection and memory acquisition
DFIR - Windows Memory Analys
Unofficial Windows proxy DLL for LeechCore 2.23 with configurable read/write audit logging, and optional write blocking for authorized debugging and testing.
Powerful investigation toolkit for deeper forensic analysis
To associate your repository with the memory-acquisition topic, visit your repo's landing page and select "manage topics."