<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Memory-Forensics on zeishr</title><link>https://theoabel.com/tags/memory-forensics/</link><description>Recent content in Memory-Forensics on zeishr</description><generator>Hugo</generator><language>en-US</language><copyright>© Théo Abel</copyright><lastBuildDate>Sun, 14 Apr 2024 15:23:05 +0000</lastBuildDate><atom:link href="https://theoabel.com/tags/memory-forensics/index.xml" rel="self" type="application/rss+xml"/><item><title>mmushell</title><link>https://theoabel.com/projects/mmushell/</link><pubDate>Sun, 14 Apr 2024 15:23:05 +0000</pubDate><guid>https://theoabel.com/projects/mmushell/</guid><description>&lt;p&gt;mmushell is a substantial fork of EURECOM&amp;rsquo;s memory-forensics proof of concept.&lt;/p&gt;
&lt;p&gt;The fork added module packaging, a Nix development shell, MkDocs documentation, and cleanup around architecture/exporter boundaries. It is archived as a research and reproducibility reference.&lt;/p&gt;</description></item><item><title>libMMU</title><link>https://theoabel.com/projects/libmmu/</link><pubDate>Mon, 11 Mar 2024 19:47:23 +0000</pubDate><guid>https://theoabel.com/projects/libmmu/</guid><description>&lt;p&gt;libMMU is a Rust crate for rebuilding virtual address spaces from memory dumps.&lt;/p&gt;
&lt;p&gt;It is inspired by OS-agnostic MMU reconstruction techniques explored in &lt;code&gt;mmushell&lt;/code&gt; and related memory-forensics research. The project is archived as a research implementation reference.&lt;/p&gt;</description></item><item><title>pyDFIRRam</title><link>https://theoabel.com/projects/pydfirram/</link><pubDate>Thu, 20 Jul 2023 12:57:16 +0000</pubDate><guid>https://theoabel.com/projects/pydfirram/</guid><description>&lt;p&gt;pyDFIRRam is a Volatility 3-based Python library for scripted and notebook-driven memory-forensics workflows.&lt;/p&gt;
&lt;p&gt;It focuses on making memory analysis easier to automate, compose, and reuse from Python rather than forcing every investigation through one-off command invocations.&lt;/p&gt;</description></item></channel></rss>