 main menuhome
forums Show me new threads!
bookmarks
post article
view blogs
vault you must be level 2 to upload files to your vault
downloads you must be logged to access downloads
Rootkit Collection
|
Windows Memory Forensic Toolkit | short description | Windows Memory Forensic Toolkit (WMFT) is a collection of utilities intended for forensic use. WMFT can be used to perform forensic analysis of physical memory images acquired from Windows 2003/XP machines. | | long description: | Windows Memory Forensic Toolkit is used to perform offline analysis of a physical memory. This is utility intended mainly for forensic-related investigative use. Current version can be used: to enumerate processes (linked by doubly linked list) and
processes hidden by DKOM, to display detailed data about each process
(e.g. info from access_token, data section control areas), to enumerate page frames which belongs to each process and to identify a process to which any
Page Frame Number belongs. | | project leader: | alcapone666 | | homepage: | http://strony.aster.pl/forensics/ | | changelog: | | | download: | link |
|