@@ -49,81 +49,81 @@ Download the latest version of **MemProcFS-Analyzer** from the [Releases](https:
4949## Usage
5050Launch Windows PowerShell (or Windows PowerShell ISE or Visual Studio Code w/ PSVersion: 5.1) as Administrator and open/run MemProcFS-Analyzer.ps1.
5151
52- 
52+ 
5353**Fig 1:** Select your Raw Physical Memory Dump and select your pagefile.sys (Optional)
5454
55- 
55+ 
5656**Fig 2:** MemProcFS-Analyzer auto-installs dependencies (First Run)
5757
58- 
58+ 
5959**Fig 3:** Accept Terms of Use (First Run)
6060
61- 
61+ 
6262**Fig 4:** If you find MemProcFS useful, please become a sponsor at: https://github.com/sponsors/ufrisk
6363
64- 
64+ 
6565**Fig 5:** You can investigate the mounted memory dump by exploring drive letter X:
6666
67- 
67+ 
6868**Fig 6:** MemProcFS-Analyzer checks for updates (Second Run)
6969
7070Note: It's recommended to uncomment/disable the "Updater" function after installation. Check out the "Main" in the bottom of the script.
7171
72- 
72+ 
7373**Fig 7:** FindEvil feature and additional analytics
7474
75- 
75+ 
7676**Fig 8:** Processes
7777
78- 
78+ 
7979**Fig 9:** Running and Exited Processes
8080
81- 
81+ 
8282**Fig 10:** Process Tree (GUI)
8383
84- 
84+ 
8585**Fig 11:** Checking Process Tree (to find anomalies)
8686
87- 
87+ 
8888**Fig 12:** Process Tree: Alert Messages w/ Process Call Chain
8989
90- 
90+ 
9191**Fig 13:** Process Tree: Properties View → Double-Click on a process or alert message
9292
93- 
93+ 
9494**Fig 14:** GeoIP w/ IPinfo.io
9595
96- 
96+ 
9797**Fig 15:** Map IPs w/ IPinfo.io
9898
99- 
99+ 
100100**Fig 16:** Processing Windows Event Logs (EVTX)
101101
102- 
102+ 
103103**Fig 17:** Zircolite - A standalone SIGMA-based detection tool for EVTX (Mini-GUI)
104104
105- 
105+ 
106106**Fig 18:** Processing extracted Amcache.hve → XLSX
107107
108- 
108+ 
109109**Fig 19:** Processing ShimCache → XLSX
110110
111- 
111+ 
112112**Fig 20:** Analyze CSV output w/ Timeline Explorer (TLE)
113113
114- 
114+ 
115115**Fig 21:** ELK Import
116116
117- 
117+ 
118118**Fig 22:** Happy ELK Hunting!
119119
120- 
120+ 
121121**Fig 23:** Multi-Threaded ClamAV Scan to help you finding evil! ;-)
122122
123- 
123+ 
124124**Fig 24:** Press **OK** to shutdown MemProcFS and Elastisearch/Kibana
125125
126- 
126+ 
127127**Fig 25:** Secure Archive Container (PW: MemProcFS)
128128
129129## Introduction MemProcFS and Memory Forensics
0 commit comments