<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; Memoryze GUI</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/memoryze-gui/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:18:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New Audit Viewer for Memoryze</title>
		<link>https://blog.mandiant.com/archives/50?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-audit-viewer-for-memoryze</link>
		<comments>https://blog.mandiant.com/archives/50#comments</comments>
		<pubDate>Tue, 25 Nov 2008 04:40:34 +0000</pubDate>
		<dc:creator>Jamie Butler</dc:creator>
				<category><![CDATA[The Lab]]></category>
		<category><![CDATA[Memory analysis]]></category>
		<category><![CDATA[memory forensics]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[Memoryze GUI]]></category>
		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=50</guid>
		<description><![CDATA[<p><a href="http://blog.mandiant.com/wp-content/uploads/2008/11/auditviewer.jpg" target="_blank"><img class="alignright size-thumbnail wp-image-54" title="auditviewer" src="http://blog.mandiant.com/wp-content/uploads/2008/11/auditviewer.jpg" alt="" width="150" height="120" /></a><br />
If you are tired of trying to load <a href="http://www.mandiant.com/software/memoryze.htm" target="_blank">Memoryze&#8217;s</a> results into Internet Explorer<br />
or into an Excel spreadsheet, check out the new viewer from Peter<br />
Silberman. The Audit Viewer is written in Python and comes with<br />
the BSD license because you know best how you want to view your data. <a href="https://blog.mandiant.com/archives/50" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.mandiant.com/wp-content/uploads/2008/11/auditviewer.jpg" target="_blank"><img class="alignright size-thumbnail wp-image-54" title="auditviewer" src="http://blog.mandiant.com/wp-content/uploads/2008/11/auditviewer.jpg" alt="" width="150" height="120" /></a><br />
If you are tired of trying to load <a href="http://www.mandiant.com/software/memoryze.htm" target="_blank">Memoryze&#8217;s</a> results into Internet Explorer<br />
or into an Excel spreadsheet, check out the new viewer from Peter<br />
Silberman. The Audit Viewer is written in Python and comes with<br />
the BSD license because you know best how you want to view your data.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 9pt; font-family: Verdana;">Audit Viewer allows the incident responder or forensic analyst to quickly view complex XML output in an easily readable format. Using familiar grouping of data and search capabilities, Audit Viewer makes memory analysis quicker and more intuitive.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">
<p><strong>Check out these features:</strong></p>
<ul>
<li><span style="font-size: 9pt; font-family: Verdana;">Process data can be viewed on a per process basis or in its entirety by double clicking the root node, “Processes”. For example, when you double click on “Processes” and then click on the Files tab, all the file handles open on the host are displayed from least frequently to most frequently occurring.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Ability to search Files, Processes, Mutants, Events, Registry Keys, and Strings using plain text or regex.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Ability to load multiple Memoryze result sets contained in the same directory.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Handle types are separated out into more abstract types representing the logical type of the handle such as Files, </span><span style="font-size: 9pt; font-family: Verdana;">Directories (part of the Object Manager’s namespace), </span><span style="font-size: 9pt; font-family: Verdana;">Processes, </span><span style="font-size: 9pt; font-family: Verdana;">Keys,</span><span style="font-size: 9pt; font-family: &quot;Courier New&quot;;"><span style="mso-list: Ignore;"><span style="font-family: &quot;Times New Roman&quot;;"> </span></span></span><span style="font-size: 9pt; font-family: Verdana;">Mutants, and </span><span style="font-size: 9pt; font-family: Verdana;">Events.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Memory sections with names are displayed under the DLLs tab.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Layered drivers are displayed in a tree view. <em style="mso-bidi-font-style: normal;">This is useful for finding certain types of keyboard sniffers, network sniffers, and file filtering drivers.<br />
</em></span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Integrated with Memoryze to seamlessly acquire drivers and processes from live memory and images.<br />
</span></li>
<li><span style="font-size: 9pt; font-family: Verdana;">Ability to scan all processes for “questionable” executable sections. <em style="mso-bidi-font-style: normal;">These sections have the EXECUTE_READWRITE flag but no name.</em> </span></li>
</ul>
<p>Get the goods, <a href="http://fred.mandiant.com/auditviewer.zip" onclick="javascript: pageTracker._trackPageview('/downloads/Memoryze_Audit_Viewer'); ">Audit Viewer 1.0.0.7</a>!  Want to learn how to harness this power? Check out <a href="http://blog.mandiant.com/wp-content/uploads/2008/11/auditvieweruserguide.pdf" onclick="javascript: pageTracker._trackPageview('/downloads/Memoryze_Audit_Viewer_PDF'); ">Audit Viewer PDF</a>.</p>
<p>Special thanks to Peter for spending his nights and weekends to make this available.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/50/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

