Windows Memory Forensics

Let’s begin with an image: Yep. That’s an icon. In an executable. In a process address space. In a raw memory dump. And here is the video demonstration: This is just a proof-of-concept. We still haven’t decided whether to develop … Continue reading

Profiler 2.5

Profiler 2.5 is out with the following news: – introduced scan provider extensions – added support for Torrent files – added the capability to display views as dialogs – exposed official Python bindings for capstone – added new controls to … Continue reading

