Vista Physical Memo...
 
Notifications
Clear all

Vista Physical Memory Forensics

20 Posts
11 Users
0 Reactions
1,891 Views
(@mckinneyb)
New Member
Joined: 17 years ago
Posts: 1
Topic starter  

Does anyone know of a tool or script to parse an image of physical memory from a vista PC?

Volatility is a fantastic framework, however it only supports XP images. When I try to run it against a vista memory image it can't recognize it.

I've found and used Andreas Schuster's PTfinder, which works, but doesn't provide near as much capability as some of the other tools available for XP images.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Have you tried Mandiant's tool?


   
ReplyQuote
kleanchap
(@kleanchap)
Active Member
Joined: 17 years ago
Posts: 19
 

I am assuming that you are trying to capture volatile memory. In the past, I have used Mandiant's mdd.exe and now there is newer tool Matthieu Suiche's win32dd.exe which looks pretty good. I haven't used it yet though.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I am assuming that you are trying to capture volatile memory.

Mdd.exe is from ManTech, not Mandiant.

In the past, I have used Mandiant's mdd.exe and now there is newer tool Matthieu Suiche's win32dd.exe which looks pretty good. I haven't used it yet though.

I'm not sure what your response has to do with the original question
"Does anyone know of a tool or script to parse an image of physical memory from a vista PC?"

It would appear that the OP already has the contents of physical memory, and is looking for a means of extracting data from it. I would suggest looking at Memoryze, from Mandiant.


   
ReplyQuote
(@rossetoecioccolato)
Eminent Member
Joined: 18 years ago
Posts: 34
 

I suppose that the OP is looking for free tools. Both Volatile Systems (https://www.volatilesystems.com/) and GMG Systems, Inc. (http//www.gmgsystemsinc.com/knttools/) offer commercial services and/or tools capable of analyzing Vista memory images. The OP will be more likely to find answers concerning these solutions if he contacts the companies directly using the contact information on their respective web pages.


   
ReplyQuote
(@xiaoheizi)
Active Member
Joined: 18 years ago
Posts: 8
 

Harlan
It seems that the tool still doesn't support vista memory image. Any other good tool for vista memory image analysis?

I am assuming that you are trying to capture volatile memory.

I'm not sure what your response has to do with the original question
"Does anyone know of a tool or script to parse an image of physical memory from a vista PC?"

It would appear that the OP already has the contents of physical memory, and is looking for a means of extracting data from it. I would suggest looking at Memoryze, from Mandiant.


   
ReplyQuote
 sfxw
(@sfxw)
Active Member
Joined: 17 years ago
Posts: 14
 

I think X-Ways Forensics v15.2 is another very good tool for Vista memory image analysis.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Harlan
It seems that the tool still doesn't support vista memory image. Any other good tool for vista memory image analysis?

I hope to look at HBGary's Responder product again soon…but am I to understand that Memoryze doesn't work with Vista memory dumps?


   
ReplyQuote
(@brede)
Trusted Member
Joined: 20 years ago
Posts: 64
 

I think X-Ways Forensics v15.2 is another very good tool for Vista memory image analysis.

v.15.2 is still in beta state..


   
ReplyQuote
(@infern0)
Trusted Member
Joined: 17 years ago
Posts: 54
 

No Vista support yet for Memoryze.

http//www.mandiant.com/software/mmdld.htm


   
ReplyQuote
Page 1 / 2
Share: