Home Contact

M-unition

The Ammunition You Need to Find Evil and Solve Crime

About Us

Welcome to M-unition, the MANDIANT blog. Here we share our insights about the tools we create and use to find evil and solve crime.

zynamics VxClass and memory analysis

Written by Jamie Butler

 
First, let me start by saying thanks to our users for the more than 10,000 unique downloads of Memoryze and Audit Viewer in 2010. Peter and I have been working with a lot of different people over the past couple of months to bring you this new release. Read the rest

Tags: , , , , , ,

Memory forensics on Windows 7 (x86 and x64) and Windows 2008 x64

Written by Jamie Butler

Next month Memoryze will be two years old and a lot has changed over that time. There has been a lot of interesting research in the field of memory forensics, and responders are finding value in the analysis.
 
Platform Support
From a tool perspective, other than the addition of a GUI called Audit Viewer and the added usability that the Malware Rating Index (MRI) provides, the most noticeable change is the expanding platform support. Read the rest

Tags: , , , , , ,

. 20 Sep 10 | The Armory | Comments (0)

New Memoryze, Audit Viewer, and Training

Written by Jamie Butler

For those who are not on our mailing list for Memoryze or Audit Viewer, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released MANDIANT Intelligent Response (MIR) 1.4. Read the rest

Tags: , , , , , ,

Honeynet Project: Challenge 3 of the Forensic Challenge 2010

Written by Helena Brito

The Honeynet Project has posted a forensic challenge centered around analyzing a memory image. The image represents the physical memory acquired from a host at a fictitious bank, which was the victim of an intruder. The Honeynet Project has come up with a series of questions that you must answer in order to solve the case. Read the rest

Tags: , , , , ,

. 09 Apr 10 | The Suite Spot | Comments (0)

Memory Analysis on Windows 2003 64-bit and What’s Next

Written by Jamie Butler

Tags: , , , , , , ,

. 15 Mar 10 | The Suite Spot | Comments (0)

Malware Behaving Badly: Preview

Written by Peter Silberman

Hope everyone on the northern east coast is staying warm during snowpaclypse. Since I can’t go anywhere I figured now is the right time to write about an upcoming webinar I am giving with Michael Graven.

The webinar entitled Malware Behaving Badly is on Thursday, February 18, at 2:00 p.m. Read the rest

Tags: , , , , , , , ,

. 12 Feb 10 | The Suite Spot | Comments (0)