Skip to content

MemProcFS-Analyzer-v0.9

Compare
Choose a tag to compare
@evild3ad evild3ad released this 25 May 06:55
· 13 commits to main since this release

Added: FS_Forensic_Yara (YARA Custom Rules)
Added: FS_Forensic_Files (incl. ClamAV)
Added: Checking for suspicious processes with double file extensions
Added: Checking for Command and Scripting Interpreters
Added: Recent Folder Artifacts
Added: Hunting Suspicious Image Mounts
Added: OpenSaveMRU (OpenSavePidlMRU)
Added: LastVisitedMRU (LastVisitedPidlMRU)
Added: Terminal Server Client (RDP)
Added: Kroll RECmd Batch File v1.21 (2023-03-04)
Added: Improved Microsoft Defender AntiVirus Handling
Added: Improved Drive Letter (Mount Point) Handling
Fixed: Other minor fixes and improvements