- Joined
- May 15, 2017
- Messages
- 981
- Likes
- 760
- Points
- 1,045
![MemProcFS_4_proc_procstruct.png](https://1.bp.blogspot.com/-Qp25ZndToAU/XYrcMrRxhAI/AAAAAAAAQaA/iTtpmlnt4NAjYPyG7-bRgruz8670tsJvQCNcBGAsYHQ/s640/MemProcFS_4_proc_procstruct.png)
The Memory Process File System is an easy and convenient way of accessing physical memory as files a virtual file system.
Easy trivial point and click memory analysis without the need for complicated commandline arguments! Access memory content and artifacts via files in a mounted virtual file system or via a feature rich application library to include in your own projects!
Analyze memory dump files, live memory via DumpIt or WinPMEM, live memory in read-write mode via linked PCILeech and PCILeech-FPGA devices!
It's even possible to connect to a remote LeechAgent memory acquisition agent over a secured connection - allowing for remote live memory incident response - even over higher latency low band-width connections!
Use your favorite tools to analyze memory - use your favorite hex editors, your python and powershell scripts, WinDbg or your favorite disassemblers and debuggers - all will work trivally with the Memory Process File System by just reading and writing files!
![MemProcFS_1_proc_base2.png](https://1.bp.blogspot.com/-FcOckQur6-s/XYrcak7sYWI/AAAAAAAAQaE/sX7_syYGJV4qbYpAe-j5DpMxikVac1Y2ACNcBGAsYHQ/s640/MemProcFS_1_proc_base2.png)
![MemProcFS_2_pciescreamer.jpeg](https://1.bp.blogspot.com/-dlt5sDNSF8M/XYrcatbpWfI/AAAAAAAAQaM/HlSYpuduDdoTldw_TqMeTZenj7cM9WfxACNcBGAsYHQ/s400/MemProcFS_2_pciescreamer.jpeg)
![MemProcFS_3_proc_modules.png](https://1.bp.blogspot.com/-eT0T4Oqr7OM/XYrcanCPfOI/AAAAAAAAQaI/SpKgqDVO0L0UkKmogdwDBhvanIhxYr1HQCNcBGAsYHQ/s640/MemProcFS_3_proc_modules.png)
Download MemProcFS