Jump to content
Nytro

SysAnalyzer

Recommended Posts

SysAnalyzer

[TABLE]

[TR]

[TH=bgcolor: #E6EBFF, align: left]Author: [/TH]

[TD] David Zimmer (iDefense Labs) [/TD]

[/TR]

[TR]

[TH=bgcolor: #E6EBFF, align: left] Website: [/TH]

[TD=colspan: 2] RE Corner [/TD]

[/TR]

[TR]

[TH=bgcolor: #E6EBFF, align: left] Current version: [/TH]

[TD=colspan: 2]

[/TD]

[/TR]

[TR]

[TH=bgcolor: #E6EBFF, align: left] Last updated: [/TH]

[TD=colspan: 2] March 21, 2011 [/TD]

[/TR]

[TR]

[TH=bgcolor: #E6EBFF, align: left] Direct D/L link: [/TH]

[TD=colspan: 2] http://sandsprite.com/CodeStuff/SysAnalyzer_Setup.exe[/TD]

[/TR]

[/TABLE]

pdate: This tool is no longer available for download through the iDefense website. An updated installer has been made available by the author.

SysAnalyzer is an automated malcode run time analysis application that monitors various aspects of system and process states. SysAnalyzer was designed to enable analysts to quickly build a comprehensive report as to the actions a binary takes on a system. SysAnalyzer can automatically monitor and compare:

* Running Processes

* Open Ports

* Loaded Drivers

* Injected Libraries

* Key Registry Changes

* APIs called by a target process

* File Modifications

* HTTP, IRC, and DNS traffic

SysAnalyzer also comes with a ProcessAnalyzer tool which can perform the following tasks:

* Create a memory dump of target process

* parse memory dump for strings

* parse strings output for exe, reg, and url references

* scan memory dump for known exploit signatures

Full GPL source for SysAnalyzer is included in the installation package.

Download:

http://sandsprite.com/CodeStuff/SysAnalyzer_Setup.exe

Sursa: Category:Registry Monitoring Tools - Collaborative RCE Tool Library

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...