Memoryze icon

Memoryze

2 big stars
Memoryze screenshot
Name: Memoryze
Works on: windowsWindows 2000 and above
Developer: Mandiant
Version: 3
Last Updated: 10 Mar 2017
Release: 30 Aug 2013
Category: Tweak > Memory Tweak
Rate this software:
428 downloads
screenshotsView Screenshots(1)
commentsComments
downloadDownload
Liked it? Tell others:
details

Memoryze Details

Works on: Windows 10 | Windows 8.1 | Windows 8 | Windows 7 | Windows XP | Windows 2000 | Windows 2003 | Windows 2008 | Windows Vista | Windows 2012
SHA1 Hash: 4f719a43c7464e1794398dde9eb1dd43af6193d7
Size: 6.99 MB
File Format: zip
Rating: 2.04347826 out of 5 based on 23 user ratings
Downloads: 428
License: Free
Memoryze is a free software by Mandiant and works on Windows 10, Windows 8.1, Windows 8, Windows 7, Windows XP, Windows 2000, Windows 2003, Windows 2008, Windows Vista, Windows 2012.
You can download Memoryze which is 6.99 MB in size and belongs to the software category Memory Tweak.
Memoryze was released on 2013-08-30 and last updated on our database on 2017-03-10 and is currently at version 3.
download button
Thank you for downloading from SoftPaz! Your download should start any moment now. It would be great if you could rate and share:
Rate this software:
Share in your network:
features

Memoryze Description

Mandiant Memoryze (formerly known as Mandiant Free Agent) is a free memory analysis utility that can not only acquire the physical memory from a Microsoft Windows system, but it can also perform advanced analysis of live memory while the computer is running. All analysis can be done either against an acquired image or a live system.

XML Scripts

Memoryze takes XML documents that define what to do, and Memoryze then outputs the result in XML format. The user can configure the individual parameters within each execution script in order to perform the desired actions.
Several default execution scripts are provided with Memoryze’s installation. These scripts include:
AcquireDriver.Batch.xml
AcquireMemory.Batch.xml
AcquireProcessMemory.Batch.xml
DriverAuditModuleList.Batch.xml
DriverAuditSignature.Batch.xml
ProcessAuditMemory.Batch.xml
RootkitAudit.Batch.xml
Each script’s options will be discussed in depth, with examples.

Batch Files

To make Memoryze easier to use, each execution script has been wrapped by a corresponding batch file. All the parameters in the XML execution script can be modified from the command line using arguments to the batch file. The batch files include:
MemoryDD.bat to acquire an image of physical memory.
ProcessDD.bat to acquire an image of the process’ address space.
DriverDD.bat to acquire an image of a driver.
Process.bat to enumerate everything about a process including handles, virtual memory, network ports, and strings.
HookDetection.bat to look for hooks within the operating system.
DriverSearch.bat to find drivers.
DriverWalkList.bat to enumerate all modules and drivers in a linked list.

Viewing the Results

Memoryze creates XML documents containing the analysis results. Currently, MANDIANT does not provide a stand-alone external viewer for Memoryze’s results. However, result files can be displayed in any XML viewer – such as Windows Internet Explorer, Mozilla Firefox, or even Microsoft Excel 2007. Be careful! Some XML viewers can be sluggish when loading large XML documents.

Executing Memoryze

There are two ways to use Memoryze.
One way is to use the XML command files native to Memoryze.exe. This requires editing the *.Batch.xml files to configure Memoryze to perform the desired tasks.
The other option is to use the command-line batch scripts provided. These batch scripts generate the XML command files for the desired audit using the options specified on the batch file command line.
Using the batch scripts eliminates the need to edit an XML file. These batch scripts are convenient for interactive use.

Using Memoryze with the XML Execution Scripts

Memoryze.exe is the executable that takes the command line parameters and executes the XML audit or script. Memoryze command line parameters are as follows:
‐o [directory]
The optional directory argument specifies the location to store the results. If this location is not specified, the results are stored by default in /Audits//. is the name of the system on which Memoryze is executing, and is a date/time stamp in the format of YYYYMMDDHHMMSS.
‐script
Executes the specified audit (*.Batch.xml)
‐encoding [none|aff|gzip]
none – no encoding of the output
aff – compresses the output in an AFF evidence container
gzip – compresses the output in GZIP
screenshots

Memoryze Screenshots

Memoryze screenshot 1
similarSimilar Software