Tag Archives: Memory Forensics

Heap & File Carving

Along with the newly released 2.9 version of Profiler Advanced, we have improved support for memory images. Before going into the main topics of this post, it is worth mentioning that loading and scanning times have been drastically improved for … Continue reading

Posted in Forensics, Memory, Profiler Advanced | Tagged , | Comments Off on Heap & File Carving

Windows Memory Forensics

Let’s begin with an image: Yep. That’s an icon. In an executable. In a process address space. In a raw memory dump. And here is the video demonstration: This is just a proof-of-concept. We still haven’t decided whether to develop … Continue reading

Posted in Demo, Forensics, Profiler | Tagged , | 3 Comments