This is by far the most useful tool introduced in your informative channel .. Many thanks for the support you are providing to us.
@muhammadhassoub2992 жыл бұрын
Great video as usual. I wait for a practical applied case using this tool
@chrisclark51352 жыл бұрын
Great find! Thanks for sharing and I'll be using this going forward for sure!
@GlobalSecure2 жыл бұрын
The best project on DFIR a ever see! amazing work!!
@MultiNamer2 жыл бұрын
Wow, Absolutely fantastic, I have dreamed of this kind of tool. So valuable, Thanks a lot.
@Bequietize2 жыл бұрын
One interesting thing which you did not show is NTFS directory in forensics, of course you have whole MFT list in one file but sometimes I don't know what am I looking for and I find it extremely helpful that you can just browse through it like C->Users->user->Downloads and you see there bunch of files and start thinking. Why are those files visible in memory? Did something loaded it up or was it downloaded with browser? Anyways, as always great content, thank you for your work :)!
@13Cubed2 жыл бұрын
About the best you can do would be to browse the contents of the $MFT as available within the memory capture. Some of those files may actually be present within memory, and recoverable. That said, there isn't a virtual directory hierarchy that re-creates the entire file system structure. Also remember that there are no guarantees in memory forensics -- what you are looking for *may* be present, or it may have been paged to disk and not available in the memory capture. Also keep in mind that at some point, everything you do on a computer system (websites you visit, pictures you view, documents you create, etc.) traverses the memory. So, there can be a lot of interesting evidence and potentially valuable content therein -- but again, just no guarantees.
@mohammedal-mudhafar4602 Жыл бұрын
This is so valuable, thanks a lot :)
@fabianoaraujodecarvalho19672 жыл бұрын
the best class, very good
@agu2272 жыл бұрын
This changes everything
@JediBuddhist2 жыл бұрын
Thats Great Thank you.
@shibly99 Жыл бұрын
This saves my day.
@HitemAriania2 жыл бұрын
Ive been using this for awhile, superglad you covered it so well! A completely other question: Is there any good tools to create a memory dump without crashing the system? Havent found one yeat.
@13Cubed2 жыл бұрын
WinPmem is usually my go-to.
@HitemAriania2 жыл бұрын
@@13Cubed Thank you kind sir! Keep up the superb work :)
@abhijitgupta90 Жыл бұрын
This is a revelation!
@johndittamo10852 жыл бұрын
What Linux distros does this support?
@moradosama90762 жыл бұрын
Great video
@alanharper5087Ай бұрын
I have issues with installing Dokany,, so I uninstalled it but the Windows uninstaller did not do a complete uninstall and I can't reinstall it because the Dokany installer thinks it is still installed. Ideas anyone?
@13CubedАй бұрын
Look at the version history for Dokany and try to install a previous release instead of the newest release. See if it will let you proceed then.
@alanharper5087Ай бұрын
@@13Cubed Thanks. I tried that but because Win10 did not fully uninstall Dokany, I cannot install any version.
@servermadum72977 ай бұрын
Thanks for video
@CookieBrainSlug2 жыл бұрын
Would MemProcFS be able to process Windows 10 hibernation files (hiberfil.sys)?
@13Cubed2 жыл бұрын
If you use Hibernation Recon to extract the active memory from hiberfil.sys, it should work. Check out the Windows Hibernation Files episode for more information on how to do that.
@stephencole92892 жыл бұрын
You can of course do most of this from a debugger on the dump, but requires a great deal of expertise (and time and effort). The forensics bit etc automates a lot of that
@tg79432 жыл бұрын
Push!
@mk72v2oq2 жыл бұрын
So it basically trying to recreate Linux (or any Unix-like system) in Windows.
@chriseastwood13102 жыл бұрын
first
@maheshbind51812 ай бұрын
This is really amazing . You are awesome as always. I generally face challenges and not getting parsed data in forensic folder. I only have four files database.txt, forensics_enable.txt, progress_percent.txt and readme.txt. The files and folders are visible for me. Does it take time if I am investigating a 17.4 gb of ram size. How long???
@13Cubed2 ай бұрын
Check the progress_percent.txt file -- that should display the percentage complete for the forensic process. It can take 15-20 minutes or longer, depending on the speed of your system and the size of the image. It should be at 100 when complete.
@mussaabdi2 жыл бұрын
Why is it only 1GB of storage?so if your memory is 10GB it keeps saying insufficient memory.KINDLY address will appreciate @13Cubed