Saturday, May 28, 2011

Memory Analysis Tools Developments

I've been a user of ResponderPro...and have used the open-source tools as well such as Volatility, Memoryze, etc...but ResponderPro really just has features and capability that make it a great tool. It saves me a lot of time and effort. It is expensive though.

However, recently HBGary released Responder CE, a community version of their paid-for Responder products. That is good news.  I haven't had the time to test it, but it may be just the thing you need to start analyzing memory in an efficient manner without some of the hiccups or issues with other tools.

This post though is actually more about the new release of Mandian Redline. Mandiant released Redline 1.0 and this looks like another great tool to use when analyzing memory.  I did get to play with a bit and it appears to be a solid tool; I will be testing it some more against some memory dumps alongside Responder to put it through it's paces.  Really like the fact I can use FDpro dumps I already have.  So far I've been really impressed.

Screenshot below of a friendly remnant of Zeus....