{"repo":"LETHAL-FORENSICS/MemProcFS-Analyzer","free":true,"listed":false,"github":"https://github.com/LETHAL-FORENSICS/MemProcFS-Analyzer","clone":"git clone https://github.com/LETHAL-FORENSICS/MemProcFS-Analyzer.git","description":"MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR","language":"PowerShell","stars":730,"topics":["powershell","incident-response","dfir","digital-forensics","memprocfs","memory-forensics","live-response"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"MemProcFS-Analyzer MemProcFS-Analyzer.ps1 is a PowerShell script utilized to simplify the usage of MemProcFS and to optimize your memory analysis workflow. MemProcFS - The Memory Process File System by Ulf Frisk https://github.com/ufrisk/MemProcFS Features: Fast and easy memory analysis! You can mount a memory snapshot (Raw Physical Memory Dump or Microsoft Crash Dump) like a disk image and handle the memory compression feature on Windows Auto-Install of MemProcFS, AmcacheParser, AppCompatCacheParser, Elasticsearch, entropy, EvtxECmd, ImportExcel, IPinfo CLI, jq, Kibana, lnk parser, RECmd, SBECmd, xsv, YARA, and Zircolite Auto-Update of MemProcFS, AmcacheParser, AppCompatCacheParser, Elasticsearch, entropy, EvtxECmd (incl. Maps), ImportExcel, IPinfo CLI, jq, Kibana, lnk parser, RECmd, SBECmd, xsv, YARA, and Zircolite Update-Info when there's a new version of ClamAV or a new Dokany File System Library Bundle available Pagefile Support OS Fingerprinting Scan w/ Custom YARA rules (incl. 447 rules by e.g. Chronicle and Elastic Security) Multi-Threaded scan w/ ClamAV for Windows Collection of infected files detected by ClamAV for further analysis (PW: infected) Collection of injected modules detected by MemProcFS PE INJECT for further analysis (PW: infected) Extracting IPv4/IPv6 IP2ASN Mapping and GeoIP w/ IPinfo CLI &#8594; Get your token for free at https://ipinfo.io/signup Checking for Suspicious Port Numbers Process Tree (TreeView) including complete Process Call Chain (Specia","default_branch":null,"files":null,"tree":[],"storefront":"/r/LETHAL-FORENSICS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/LETHAL-FORENSICS/MemProcFS-Analyzer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}