2Likes -
2 Post By nivels
-
Software Developer/Security Expert
WriteProcessMemory Monitor v1.0 (freeware)
WriteProcessMemory API Monitor is a Windows OS utility designed solely to monitor processes in the system that write to other process’ virtual address spaces. Malware often uses such techniques in order to write payload stubs to a foreign process to hook an API, load a malware DLL etc. ntdll!NtWriteVirtualMemory is hooked in order to achieve the desired logging functionality in usermode.
WriteProcessMemory API Monitor displays the caller process and target process filenames as well as their respective process identifiers are shown along with the size of the buffer written to the process and the actual contents represented in hexadecimal of the buffer. The location of the written memory is also listed in hex for run-time reverse engineering convenience.
WriteProcessMemory API Monitor can easily be integrated into malware or rootkit test environments to help the security researcher reverse analyze a piece of malware alongside other powerful tools.
Product Page:
http://www.novirusthanks.org/product/writeprocessmemory-monitor/
Download Installer:
http://downloads.novirusthanks.org/files/wpm_monitor_setup.exe
Download Portable:
http://downloads.novirusthanks.org/files/portables/wpm_monitor_portable.zip
-
*nix Technical Support
Nivels, no offense, but is there any chance NoVirusThanks might roll out a Task Manager replacement?
pacman -Syyu life not found in sync db
Similar Threads
-
By nivels in forum Security Bulletin
Replies: 1
Last Post: 12-20-2011, 11:09 PM
-
By FunkY in forum Latest Releases
Replies: 1
Last Post: 03-03-2011, 11:58 AM
-
By detailer in forum Freebies!
Replies: 2
Last Post: 05-16-2009, 12:38 PM
-
By wan_tp in forum General Forum
Replies: 1
Last Post: 08-31-2008, 11:02 AM
-
By Sven in forum Software
Replies: 3
Last Post: 03-22-2008, 02:21 PM
Tags for this Thread
All times are GMT +8. The time now is 06:18 AM.