Quantcast
Channel: DFIR Training - Recently Added Listings
Viewing all articles
Browse latest Browse all 888

MemProcFS

$
0
0

The Memory Process File System:

The Memory Process File System is an easy and convenient way of accessing physical memory as files a virtual file system.

Easy trivial point and click memory analysis without the need for complicated commandline arguments! Access physical memory content and artifacts via files in a mounted virtual file system or via a feature rich .dll application library to include in your own projects!

Analyze memory dump files - or even live memory in read-write mode via linked pcileech and pcileech-fpga devices!

Use your favorite tools to analyze memory - use your favorite hex editors, your python and powershell scripts, your disassemblers - all will work trivally with the Memory Process File System by just reading and writing files!


Category: Memory
Category URL: http://www.dfir.training/component/mtree/forensic-utilities/memory?Itemid=

Viewing all articles
Browse latest Browse all 888

Latest Images

Trending Articles



Latest Images