MemProcFS Analyzer: Automated Forensic Analysis of Windows Memory Dumps
MemProcFS Analyzer
MemProcFS-Analyzer.ps1 is a PowerShell script utilized to simplify the usage of MemProcFS and to assist with the analysis workflow.
Features:
- Auto-Install of MemProcFS, EvtxECmd, Elasticsearch, Kibana
- Auto-Update of MemProcFS, EvtxECmd (incl. Maps), Elasticsearch, Kibana, ClamAV Virus Databases (CVD)
- Update-Info when there’s a new version of ClamAV or a new Redistributable packaged Dokany Library Bundle available
- Multi-Threaded scan w/ ClamAV for Windows
- Extracting IPv4/IPv6
- IP2ASN Mapping w/ Team Cymru
- Checking for Unusual Parent-Child Relationships
- Extracting Windows Event Log Files and processing w/ EvtxECmd → Timeline Explorer (EZTools by Eric Zimmerman)
- Collecting Evidence Files (Secure Archive Container → PW: MemProcFS)
Usage
Launch Windows PowerShell ISE or Visual Studio Code (PSVersion: 5.1) as Administrator and open/run MemProcFS-Analyzer.ps1.
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/File-Browser.png)
Fig 1: Select your Raw Physical Memory Dump
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/Auto-Install-1024x416.png)
Fig 2: MemProcFS-Analyzer checks for dependencies (First Run)
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/Microsoft-Internet-Symbol-Store.png)
Fig 3: Accept Terms of Use (First Run)
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/ClamAV-Scan-1024x299.png)
Fig 4: Multi-Threaded ClamAV Scan
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/Elasticsearch-1024x350.png)
Fig 5: Processing Windows Event Logs (EVTX)
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/ELK-Import-1024x699.png)
Fig 6: ELK Import
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/ELK-Timeline-1024x510.png)
Fig 7: Happy ELK Hunting!
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/Secure-Archive-Container-1024x298.png)
Fig 8: ClamAV Scan found 29 infected file(s)
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/Message-Box.png)
Fig 9: Press OK to shutdown MemProcFS and Elastisearch/Kibana
![](https://cdn-0.meterpreter.org/wp-content/uploads/2025/01/ELK-Import-1-1024x699.png)
Fig 10: Secure Archive Container (PW: MemProcFS)
Download
Copyright (C) 2021 evild3ad