Memory forensics on Windows 7 (x86 and x64) and Windows 2008 x64
Written by Jamie Butler
Next month Memoryze will be two years old and a lot has changed over that time. There has been a lot of interesting research in the field of memory forensics, and responders are finding value in the analysis.
Platform Support
From a tool perspective, other than the addition of a GUI called Audit Viewer and the added usability that the Malware Rating Index (MRI) provides, the most noticeable change is the expanding platform support. Read the rest
Tags: DKOM attacks, Memory analysis, memory forensics, Memoryze, rootkits, Windows 2008, Windows 7
New Memoryze, Audit Viewer, and Training
Written by Jamie Butler
For those who are not on our mailing list for Memoryze or Audit Viewer, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released MANDIANT Intelligent Response (MIR) 1.4. Read the rest
Tags: Advanced Memory Forensics in Incident Response, Audit Viewer, Black Hat, memory forensics, Memoryze, MIR 1.4, Training
Memory Analysis on Windows 2003 64-bit and What’s Next
Written by Jamie Butler
Peter and I have been busy planning for CanSecWest in a week. The course, Advanced Memory Forensics in Incident Response, is constantly evolving. It has been about a year and a half since Memoryze was released, and just over a year for Audit Viewer.
Tags: Audit Viewer, Black Hat USA, CanSecWest, Malware Rating Index, Memory analysis, memory forensics, Memoryze, MRI
New Audit Viewer for Memoryze
Written by Jamie Butler

If you are tired of trying to load Memoryze’s results into Internet Explorer
or into an Excel spreadsheet, check out the new viewer from Peter
Silberman. The Audit Viewer is written in Python and comes with
the BSD license because you know best how you want to view your data. Read the rest
Tags: Memory analysis, memory forensics, Memoryze, Memoryze GUI, open source

