xosski

MemForensics

Feb 9th, 2026
95
0
Never
7
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.57 KB | None | 0 0
  1. Advanced Memory Forensic Toolkit
  2. A comprehensive, cross-platform memory forensics analysis platform with PyQt6 GUI. Integrates active memory acquisition, deleted file recovery, unallocated space scanning, process analysis, and malware detection.
  3. github.com/xosski/MemForensics
  4. Features
  5. 1. Active Memory Dump
  6. Full Memory Acquisition: Dump entire physical RAM
  7. Windows: Using WinPmem driver or Win32 API fallback
  8. Linux: Using /proc/kcore, /dev/mem, or dd
  9. Process Memory Dump: Extract specific process memory space
  10. Progress Tracking: Real-time dump progress with statistics
  11. Admin Detection: Verifies required privileges before attempting dump
  12. 2. Memory Dump Analysis
  13. Chunk-based analysis of memory dumps (1MB regions)
  14. Shannon entropy calculation (detects obfuscation/encryption)
  15. String extraction:
  16. ASCII strings (printable characters)
  17. Unicode strings (UTF-16)
  18. Hash generation: MD5, SHA256 for quick identification
  19. Code injection detection
  20. Shellcode pattern matching
  21. API hook detection
  22. 3. File Carving
  23. Recovers deleted images and videos from disk:
  24.  
  25. Supported Formats:
  26. Images: JPEG, PNG, GIF, BMP, TIFF
  27. Videos: MP4, AVI, MOV, MKV, WebM
  28. Documents: PDF, ZIP, RAR
  29. Recovery Methods:
  30. Header-based carving
  31. Footer validation for enhanced accuracy
  32. Confidence scoring
  33. Entropy-based validation
  34. Batch Recovery: Recover multiple files to output directory
  35. 4. Unallocated Space Scanner
  36. Forensic artifact detection from unallocated disk space:
  37.  
  38. File Headers: Detects deleted file signatures
  39. Text Artifacts:
  40. URLs and email addresses
  41. File paths (Windows and Linux)
  42. Database Records:
  43. SQLite databases
  44. Windows Registry hives
  45. Event logs
  46. Memory Structures: Dumped heap and stack data
  47. Sector-Based Scanning: Scan specific disk ranges
  48. 5. Live Process Analysis
  49. Real-time process enumeration
  50. Detailed process information:
  51. Memory usage (RSS, VMS, etc.)
  52. Open file handles
  53. Network connections
  54. Thread count
  55. Child processes
  56. Suspicious process detection
  57. Process relationship mapping
  58. 6. Signature Scanning
  59. Malware pattern detection:
  60.  
  61. Shellcode identification
  62. DLL injection patterns
  63. API call hooks
  64. Network communication signatures
  65. Registry persistence patterns
  66. Code cave detection
  67. Embedded executable detection
  68. 7. System Health Monitoring
  69. CPU usage and core count
  70. Memory statistics
  71. Disk usage metrics
  72. Active process monitoring
  73. System Requirements
  74. Windows
  75. Windows 7 or later
  76. Administrator privileges (for memory dumping)
  77. Python 3.8+
  78. Optional: WinPmem driver for improved memory acquisition
  79. Linux
  80. Linux kernel 3.0+
  81. Root privileges (for memory/device access)
  82. Python 3.8+
  83. Tools: dd, file, openssl
Tags: forensics
Advertisement
Comments
  • Vinzotor
    51 days
    # CSS 0.85 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from Swapzone — instant swap).
  • Sarzeonoz
    50 days
    # CSS 0.84 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from Swapzone — instant swap).
  • Xorloutov
    48 days
    # CSS 0.05 KB | 0 0
    1. You literally stole it from https://t.me/theprotocolone
  • Ravbelon
    28 days
    # CSS 0.85 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1ifNm-s74mX7GChaEzSJ1dVQCy1SrSxlMVRYi8ys0rgQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
  • Mirmadorn
    27 days
    # CSS 0.85 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1ifNm-s74mX7GChaEzSJ1dVQCy1SrSxlMVRYi8ys0rgQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
  • User was banned
  • Ravvelir
    14 days
    # CSS 0.85 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1ifNm-s74mX7GChaEzSJ1dVQCy1SrSxlMVRYi8ys0rgQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
Add Comment
Please, Sign In to add comment