├── LICENSE ├── README.md ├── imgs ├── Network IOC Enrichment.jpg ├── PLACEHOLDER ├── Process Tree Visualisation - MSTICPY.jpg ├── Timeseries - MSTICPY.jpg └── csv-generation.jpg ├── memOptix-analyst.ipynb ├── msticpyconfig.yaml └── testdata ├── README.txt ├── windows.callbacks.Callbacks.csv ├── windows.cmdline.CmdLine.csv ├── windows.dlllist.DllList.csv ├── windows.driverscan.DriverScan.csv ├── windows.handles.Handles.csv ├── windows.ldrmodules.LdrModules.csv ├── windows.malfind.Malfind.csv ├── windows.modules.Modules.csv ├── windows.netscan.NetScan.csv ├── windows.pslist.PsList.csv ├── windows.ssdt.SSDT.csv └── windows.svcscan.SvcScan.csv /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/README.md -------------------------------------------------------------------------------- /imgs/Network IOC Enrichment.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/imgs/Network IOC Enrichment.jpg -------------------------------------------------------------------------------- /imgs/PLACEHOLDER: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /imgs/Process Tree Visualisation - MSTICPY.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/imgs/Process Tree Visualisation - MSTICPY.jpg -------------------------------------------------------------------------------- /imgs/Timeseries - MSTICPY.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/imgs/Timeseries - MSTICPY.jpg -------------------------------------------------------------------------------- /imgs/csv-generation.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/imgs/csv-generation.jpg -------------------------------------------------------------------------------- /memOptix-analyst.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/memOptix-analyst.ipynb -------------------------------------------------------------------------------- /msticpyconfig.yaml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/msticpyconfig.yaml -------------------------------------------------------------------------------- /testdata/README.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/README.txt -------------------------------------------------------------------------------- /testdata/windows.callbacks.Callbacks.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.callbacks.Callbacks.csv -------------------------------------------------------------------------------- /testdata/windows.cmdline.CmdLine.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.cmdline.CmdLine.csv -------------------------------------------------------------------------------- /testdata/windows.dlllist.DllList.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.dlllist.DllList.csv -------------------------------------------------------------------------------- /testdata/windows.driverscan.DriverScan.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.driverscan.DriverScan.csv -------------------------------------------------------------------------------- /testdata/windows.handles.Handles.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.handles.Handles.csv -------------------------------------------------------------------------------- /testdata/windows.ldrmodules.LdrModules.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.ldrmodules.LdrModules.csv -------------------------------------------------------------------------------- /testdata/windows.malfind.Malfind.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.malfind.Malfind.csv -------------------------------------------------------------------------------- /testdata/windows.modules.Modules.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.modules.Modules.csv -------------------------------------------------------------------------------- /testdata/windows.netscan.NetScan.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.netscan.NetScan.csv -------------------------------------------------------------------------------- /testdata/windows.pslist.PsList.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.pslist.PsList.csv -------------------------------------------------------------------------------- /testdata/windows.ssdt.SSDT.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.ssdt.SSDT.csv -------------------------------------------------------------------------------- /testdata/windows.svcscan.SvcScan.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/blueteam0ps/memOptix/HEAD/testdata/windows.svcscan.SvcScan.csv --------------------------------------------------------------------------------