#MemProcFS

Pen Test PartnersPTP@infosec.exchange
2024-10-31

Memory mounting with MemProcFS? This changes everything...

Our Luke Davis dives into MemProcFS in our latest blog, exploring how this tool has transformed memory forensics. MemProcFS allows memory dumps to be mounted and browsed like file systems, making complex memory structures easy to analyse. 💻

Using MemProcFS, investigators can:

Quickly analyse suspicious processes, like tracking Excel launching malicious code

Monitor network connections tied to ransomware groups and other threats

Explore advanced features like memory timelines and registry browsing to trace system activity and investigate security breaches 🔍

This post is a must-read for anyone delving into digital forensics or curious about memory mounting: 🔗pentestpartners.com/security-b

#MemoryForensics #MemProcFS #DigitalForensics #Cybersecurity #MalwareAnalysis #Infosec

Milos ConstantinTinolle@hachyderm.io
2023-07-07

#MemProcFS is an easy and convenient way of viewing physical memory as files in a virtual file system github.com/ufrisk/MemProcFS

2023-05-27

First free day I've had in a few weeks so I felt it was time for a new blog post!

Check out "VMware Memory Analysis with MemProcFS"

Huge thanks to @UlfFrisk for creating this incredible tool.

blog.ecapuano.com/p/vmware-mem

#DFIR #memprocfs

buheratorbuherator
2019-03-17

RT @SkelSec@twitter.com

is in now!
You mount a live system/memory image, you get a new windows drive then you browse a folder then !BAM! Logon sessions start popping up as txt files with NT/LM/SHA1 secrets AND ALSO KERBEROS KIRBI FILES!!!
Thanks to @UlfFrisk@twitter.com for helping me out!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst