Skip to content

These are some memory samples from some CTFs or simulations or IR events with some sample walkthroughs/solutions

License

Notifications You must be signed in to change notification settings

Panagiotis-INS/Memory-Forensic-Samples-Solutions

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

26 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Memory-Forensic-Samples-Solutions

These are some memory samples from some CTFs or simulations or IR events with some sample walkthroughs/solutions

Memory Samples

Links to various memory samples:




WannaCry Memory Analysis

Sample: Windows XP SP3

Original Link: https://www.null0x4d5a.com/2017/05/memory-analsyis-of-wannacry-ransomware.html

Mega Link: https://mega.nz/#!Au5xlCAS!KX5ZJKYzQgDHSa72lPFwqKL6CsZS7oQGbyyQrMTH9XY


Securinets Quals 2019 -Contact_Me

Sample: MacSierra_10_12_6_16G23ax64

Volatility 2 Profile: https://github.com/volatilityfoundation/profiles/blob/master/Mac/10.12/Sierra_10.12.6_16G23a.zip

Original Link: https://stuxnet999.github.io/securinets-ctf/2019/08/24/SecurinetsQuals2019-Contact-Me.html

Mega Link: https://mega.nz/#!L6QVyA5T!GYhexxkkraKvcV6Q6jhf08-xw0x_1X9Nzz9hAF8PuwE


Malware Cookbook

Sample: Various

Original Link: https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples

SendSpace Link: https://www.sendspace.com/pro/dl/p87m18


Links to Memory Samples from Volatility

Sample: Various

Original Link: https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples


PSExec.py Activity

Sample: Windows Server 2012

Infected: https://mega.nz/file/FwRFTa5a#0uoSJK3KsJhnytSAtwDm8onv2cHm9zdf8m6flmlP_Ts

Clean: https://mega.nz/file/FhQHXIoB#WqzU5XV6fDs6QbcglMYmJkHmX7ExE2ZHG8o9AbTg5is




Magnet CTF Week 9 - Digging Through Memory

Sample: Windows 7 SP1 x64

Original Link: https://dfir.science/2020/12/Magnet-CTF-Week-9-digging-through-memory.html

Google Drive Link: https://drive.google.com/drive/folders/1iCxOKhfoHvxoBRNXJlm2VBiAVgDD_p5d


Houseplant CTF 2020 - Imagery

Sample: Windows 10 Build 17763 x64

Original Link: https://ctftime.org/writeup/20330

Mega Link: https://mega.nz/file/R00hgCIa#e0gMZjsGI0cqw88GzbEzKhcijWGTEPQsst4QMfRlNqg


AboutDFIR

Sample: Various (look for Memory)

Original Link: https://aboutdfir.com/education/challenges-ctfs/


About

These are some memory samples from some CTFs or simulations or IR events with some sample walkthroughs/solutions

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages