Heap & File Carving

Along with the newly released 2.9 version of Profiler Advanced, we have improved support for memory images. Before going into the main topics of this post, it is worth mentioning that loading and scanning times have been drastically improved for

Windows Memory Forensics

Let's begin with an image: Yep. That's an icon. In an executable. In a process address space. In a raw memory dump. And here is the video demonstration: This is just a proof-of-concept. We still haven't decided whether to develop

