extracting-memory-artifacts-with-rekall
mukul975/Anthropic-Cybersecurity-Skills
Analyzes Windows memory dumps with Rekall to expose process hollowing, injected code, hidden processes, and suspicious DLLs during incident response, red-team, or malware analysis work by running plugins such as pslist, malfind, netscan, and dlllist.