Skip to content

MemProcFS-Analyzer-v0.7

Compare
Choose a tag to compare
@evild3ad evild3ad released this 21 Nov 06:19
· 42 commits to main since this release
52ad013

Added: User Interface
Added: Pagefile Support
Added: Zircolite - A standalone SIGMA-based detection tool for EVTX
Added: Event Log Overview
Added: Processes w/ Unusual User Context
Added: Process Tree: Properties View
Added: Searching for Cobalt Strike Beacons Configuration(s) w/ 1768.py (needs to be installed manually, disabled by default)
Added: Simple Prefetch View (based on Forensic Timeline)
Fixed: Other minor fixes and improvements