Thursday, July 28, 2011

MoonSols BlackMoon Memory Analyst

So I got lucky enough to take a look at the memory analysis tool being developed by MoonSols called BlackMoon Memory Analyst.  Currently the tool is in Beta, but already it is looking to be a pretty solid memory analysis tool.

I can only compare it to the tools I have used such as: ResponderPro, Memoryze/Auditviewer, limited exposure to Volatility, and have worked with the fairly new Redline.  From the current looks of things BlackMoon Memory Analyst will be real nice option to take a look at when you are evaluating what you want to use.

It has a nice clean interface and navigating it is pretty easy.  I did have some issues navigating or finding things, but that could be primarily because I am slow. The tool is still in Beta so there are still some kinks in my testing. I am learning some of the functionality without reading the manual (bah! who needs a manual) so you have to take that into consideration... :)  If you've done memory analysis before though, it isn't very hard to find what you are looking for.

When initially opening it you get the choice of opening a raw memory dump, hibernation file, or Microsoft crash dump.  It has a report function that dumps out to .xml format so it should be digestible by a whole host of systems you may be able to use for IOC analysis across the enterpise.

Just some screen shots:







As a side note: MoonSols recently released their quick and easy DumpIt memory tool.  It is fast!! Check it out here: http://www.moonsols.com/2011/07/18/moonsols-dumpit-goes-mainstream/