05 Mar 2009 @ 7:38 AM 
 

MANDIANT Memoryze – free memory forensic software

 

MANDIANT Memoryze – free memory forensic software

http://www.mandiant.com/software/memoryze.htm

 MANDIANT Memoryze is free memory forensic software that helps incident responders find evil in live memory. Memoryze can acquire and/or analyze memory images, and on live systems can include the paging file in its analysis.

MANDIANT Memoryze can:

    * image the full range of system memory (not reliant on API calls).
    * image a process’ entire address space to disk. This includes a process’ loaded DLLs, EXEs, heaps, and stacks.
    * image a specified driver or all drivers loaded in memory to disk.
    * enumerate all running processes (including those hidden by rootkits). For each process, Memoryze can:
          o report all open handles in a process (for example, all files, registry keys, etc.).
          o list the virtual address space of a given process including:
                + displaying all loaded DLLs.
                + displaying all allocated portions of the heap and execution stack.
          o list all network sockets that the process has open, including any hidden by rootkits.
          o output all strings in memory on a per process basis.
    * identify all drivers loaded in memory, including those hidden by rootkits.
    * report device and driver layering, which can be used to intercept network packets, keystrokes and file activity.
    * identify all loaded kernel modules by walking a linked list.
    * identify hooks (often used by rootkits) in the System Call Table, the Interrupt Descriptor Tables (IDTs), and driver function tables (IRP tables).

Tags Tags: ,
Categories: Security, System
Posted By: Jason
Last Edit: 05 Mar 2009 @ 07 38 AM

EmailPermalink
 

Responses to this post » (None)

 

Post a Comment

You must be logged in to post a comment.

 Comment Meta:
RSS Feed for comments
\/ More Options ...
Change Theme...
  • Users » 2
  • Posts/Pages » 3,500
  • Comments » 79
Change Theme...
  • VoidVoid « Default
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LightLight

.NET



    No Child Pages.

About



    No Child Pages.

Contact



    No Child Pages.