Memory Analysis Package 0.5
内存分析包0.5版发布,新增超链接进程模块、快速跳转分析、选择性扫描等功能,支持YARA规则和文件挖掘工具,提升效率与深度。 2025-7-29 09:58:59 Author: blog.cerbero.io(查看原文) 阅读量:22 收藏

Skip to content

We’ve released version 0.5 of the Memory Analysis package, currently in beta, and have also made it available to personal licenses of Cerbero Suite!

One of the cool features we worked on is hyperlinking processes and modules, allowing you to jump directly to a process or module analysis from any view. When opening a memory dump, you can choose to skip scanning processes and modules for faster inspection—yet still jump directly to a specific module and inspect it.

Why scan everything when you only need what matters? Apart from being able to skip scanning processes in a memory dump or scan all of them, we’ve added the capability to scan only processes of interest — making your analysis faster and more focused.

Modules and files can, as usual, be scanned using YARA. Additionally, the user-mode memory of processes can be scanned using our cutting-edge YARA Rules package.

User-mode memory can also be mined for files using our advanced File Miner package.

We’re continuing to expand the functionality of the Memory Analysis package with the goal of making it a state-of-the-art solution for memory forensic examiners. With each update, we’re adding powerful new features and refining the experience to support fast, focused, and in-depth analysis. More is on the way.


文章来源: https://blog.cerbero.io/memory-analysis-package-0-5/
如有侵权请联系:admin#unsafe.sh