This program allows the user to access a Memory Dump. It can also function as a plugin to the Volatility Framework (https://github.com/volatilityfoundation/volatility). This program functions similarly to Process Explorer/Hacker, but additionally it allows the user access to a Memory Dump (or access the real-time memory on the computer using Memtriage). This program can run from Windows, Linux and MacOS machines, but can only use Windows memory images.
Quick Start
- Download the volexp.py file (download the memtriage.py file as well and replace it with your memtriage.py file if you want to use memtriage https://github.com/gleeda/memtriage).
- Run as a standalone program or as a plugin to Volatility:
- As a standalone program:
python2 volexp
- As a Volatility plugin:
python2 vol.py -f <memory file path> --profile=<memory profile> volexp
Some Features:
python2 memtriage.py --plugins=volexp
- Some of the information display will not update in real time (except Processes info(update slowly), real time functions like struct analyzer, PE properties, run real time plugin, etc.).
- The program also allows to view Loaded dll's, open handles and network connections of each process (Access to a dll's properties is also optional).
- To present more information of a process, Double-Click (or Left-Click and select Properties) to bring up an information window.
- Or present more information on any PE.
- The program allows the user to view the files in the Memory Dump as well as their information. Additionally, it allows the user to extract those files (HexDump/strings view is also optional).
- The program supports viewing of the Windows Objects and files's matadata (MFT).
- The program also support viewing a regview of the memory dump
- Additionally, the program supports struct analysis. (writing on the memory's struct, running Volatility functions on a struct is available). Example of getting all the load modules inside _EPROCESS struct in another struct analyzer window:
- The Program is also capable of automatically marking suspicious processes found by another plugin. Example of a running threadmap plugin:
- View memory use of a process.
- Manually marking a certain process and adding a sidenote on it.
- User's actions can be saved on a seperate file for later usage.
get help: https://github.com/memoryforensics1/VolExp/wiki/VolExp-help:
via KitPloit Continue reading
- Nsa Hack Tools Download
- Best Pentesting Tools 2018
- Hacker Tools For Pc
- Hacking Tools 2020
- How To Make Hacking Tools
- Hacking Tools Free Download
- Pentest Tools For Ubuntu
- Hack Tools
- Hacking Tools 2020
- Hacking Tools Windows
- Hacking Tools 2020
- Blackhat Hacker Tools
- Hacker Hardware Tools
- Black Hat Hacker Tools
- Hack Tools Pc
- Hack Tools
- Pentest Tools Free
- Free Pentest Tools For Windows
- Hacking Tools And Software
- Hack Tools Download
- Tools Used For Hacking
- Install Pentest Tools Ubuntu
- New Hack Tools
- Hacking Apps
- Blackhat Hacker Tools
- Hacker Tools Windows
- Hacking Tools Usb
- Hacking Tools For Games
- Hack Tools
- Hacking Tools Windows 10
- Pentest Tools Linux
- Hack Tools Download
- Termux Hacking Tools 2019
- Kik Hack Tools
- Termux Hacking Tools 2019
- Blackhat Hacker Tools
- Pentest Tools Nmap
- Hacking App
- Pentest Tools Nmap
- Tools 4 Hack
- Hack Tools 2019
- Hacker Tools
- Hacking Apps
- Physical Pentest Tools
- Hacking Tools Github
- New Hack Tools
- Hacker Tools Apk Download
- Hacking Tools Hardware
- Pentest Tools Url Fuzzer
- Hacking Tools Download
- Beginner Hacker Tools
- Physical Pentest Tools
- Pentest Tools Bluekeep
- New Hack Tools
- Hacking Tools Free Download
- Pentest Tools Open Source
- Hacking Tools For Kali Linux
- Hacker Tools Linux
- Hacking Tools For Kali Linux
- Hacking Tools And Software
- Hack Rom Tools
- Pentest Tools Url Fuzzer
- Pentest Tools Android
- Hacker Tools 2020
- Pentest Tools Online
- Github Hacking Tools
- Pentest Tools List
- Install Pentest Tools Ubuntu
- Blackhat Hacker Tools
- Top Pentest Tools
- Hacking Tools Kit
- Hacking Tools For Windows Free Download
- Top Pentest Tools
- Hackrf Tools
- Usb Pentest Tools
- Nsa Hacker Tools
- Hacker Tools List
- Hacker Tool Kit
- Hacker Tool Kit
- Hacker Techniques Tools And Incident Handling
- Blackhat Hacker Tools
- Hacking Tools Software
- Pentest Tools Download
- Hacker Tools For Windows
- New Hacker Tools
- What Is Hacking Tools
- Hacking Tools For Beginners
- Hacking Tools And Software
- Computer Hacker
- Hacker Tools Linux
- Beginner Hacker Tools
- Pentest Tools Review
- Pentest Tools Tcp Port Scanner
- Hacking Tools Hardware
- Pentest Tools Alternative
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Windows Free Download
- Hack Tools Github
- Hacker Tools Linux
- Hacking Tools For Mac
- Pentest Tools Port Scanner
- Hack Tools For Windows
- Hacker Tools List
- Nsa Hack Tools
- How To Make Hacking Tools
- Hacking Tools For Pc
- Pentest Tools Find Subdomains
- Top Pentest Tools
- Hack Tools For Games
- Hacking Tools Kit
- Pentest Box Tools Download
- Hacking Tools Download
- Hacking Tools For Windows
- Hacker
- Wifi Hacker Tools For Windows
- Pentest Reporting Tools
- Pentest Tools Bluekeep
- Hacking Tools For Kali Linux
- Hacker Tools Github
- Hacker Tools Free
- Best Pentesting Tools 2018
- Pentest Tools Bluekeep
- Hack Tools For Windows
- Android Hack Tools Github
- Hack Website Online Tool
- Pentest Tools Windows
- Nsa Hack Tools
- Hacker Tool Kit
- Hacker Tools 2020
- Hack Tool Apk
- Pentest Tools Kali Linux
- Pentest Tools Download
- Hackrf Tools
- Hacker Tool Kit
- Pentest Tools Framework
- Hacking Tools For Kali Linux
- Hacking Tools For Mac
Nenhum comentário:
Postar um comentário