Tools:Memory Analysis

From ForensicsWiki
Jump to: navigation, search

The following tools can be used to conduct memory analysis.

Memory Analysis Frameworks

Browser Email Memory Tool

  • pdgmail is a python script to extract gmail artifacts from memory images. Made for images extracted with pdd, but works with any memory image.

Instant Messenger Memory Tool

Platform Independent Tools

A list of tools which should work regardless of future incremental OS / hardware updates.

  • Open Source Hypervisor/Process/Kernel detection for Windows, FreeBSD, OpenBSD and NetBSD. is based on interpreting low-level hardware defined constructs which change little over time. See github for details.
  • Forensics MemDump Extractor, is a tool by Gem George which can extract any kind of files residing in memory dump based on file signature. For example, if we put signature of a JPG file, it will extract all JPGs residing in memory dump.