Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 10th, 2008, 06:09 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Free new program Memoryze pinpoints malware code in live memory

http://blogs.zdnet.com/security/?p=2150
  #2  
Old November 10th, 2008, 06:51 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Free new program Memoryze pinpoints malware code in live memory

Looks good but doesn't seem to support Vista?
Quote:
Memoryze supports:

* Windows 2000 Service Pack 4
* Windows XP Service Pack 2 and Service Pack 3 (32-bit)
* Windows 2003 Service Pack 2 (32-bit)

Most service packs within a major version of the operating system will work, but the focus was on these.
  #3  
Old November 10th, 2008, 07:05 PM
optigrab's Avatar
optigrab optigrab is offline
Frequent Poster
 
Join Date: Nov 2002
Location: Brooklyn/NYC USA
Posts: 624
Default Re: Free new program Memoryze pinpoints malware code in live memory

I read the features list, but I don't know enough to answer this question: Does Memoryze work in the same way as BoClean?
__________________
Win7: Avast! AV, SandBoxie, Paragon Backup & Recovery 11 Home, Shadow Defender
  #4  
Old November 10th, 2008, 07:17 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Free new program Memoryze pinpoints malware code in live memory

Quote:
Originally Posted by optigrab
I read the features list, but I don't know enough to answer this question: Does Memoryze work in the same way as BoClean?

No - Memoryze, from what I've read, is a forensics program.
  #5  
Old November 10th, 2008, 09:37 PM
Trespasser's Avatar
Trespasser Trespasser is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Clintwood, Virginia
Posts: 967
Default Re: Free new program Memoryze pinpoints malware code in live memory

Appears to just report what is going on in memory.
__________________
Ubuntu Precise (Cinnamon DE) 12.04 32bit on one laptop, Ubuntu Precise Gnome Fallback 12.04 32bit on another laptop, Ubuntu Precise (Cinnamon DE) 12.04 64bit on our main Desktop, and Xubuntu 12.04 64bit on our spare Desktop.


"I wish I knew as much as I think I do"...
  #6  
Old November 11th, 2008, 10:37 AM
PROROOTECT's Avatar
PROROOTECT PROROOTECT is offline
Very Frequent Poster
 
Join Date: May 2008
Location: HERE ...Fort Lee, NJ
Posts: 1,102
Default Re: Free new program Memoryze pinpoints malware code in live memory

For me- it is illegible. Riddle: is it for developpers?

PS. For Mandiant Red Courtain ( sehr gut, super ) look to thread ( in software & services ) : Your NEW BEST Free Softwares ... , #99.
For excellent anti-rootkit: see KX-Ray ...
__________________
W.XPSP2,1GBRAM,13proc,17svc;IE8s ***
On-Demand
PowerTool XueTr NVT Ga S RFS
Preventive+
FW!! S.Mon. TinyW. JS SettingsX NoDs . =
URL checkZ Q W T U urlQ W IPduh DNS-info Sleuth
R W WPT BC WS M BShotSu C $ Rev IP
NoAV,Java JRE-Why Why|VOP MalwareTips-Turin Shroud PSus **READs!!! CATS!
  #7  
Old November 12th, 2008, 10:03 AM
dw2108 dw2108 is offline
Frequent Poster
 
Join Date: Jan 2006
Posts: 468
Default Re: Free new program Memoryze pinpoints malware code in live memory

That site looks exactly like the NictaTech AV site. Clones concern me.

Dave
  #8  
Old November 12th, 2008, 02:02 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Free new program Memoryze pinpoints malware code in live memory

Don't know about that but Memoryze is a very nice tool produced by some top pros in this field. The company can be said to be similar to HBGary with various other services.

(edit : don't forget their other tools, first response, red curtain, web historian.)
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 12th, 2008 at 09:27 PM. Reason: corrected Memoryze spelling
  #9  
Old November 13th, 2008, 10:49 PM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,510
Default Re: Free new program Memoryze pinpoints malware code in live memory

Hey

Is there a way to test this app? Just a little lost with something this new like this.

Interested in seeing if it can serve some useful purpose or not in this army of defense i deploy.

Thanks EASTER
__________________
★AX 64 Time MachineCurrent Version 1.1.0.996 ★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Reserve Space|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #10  
Old November 14th, 2008, 11:53 PM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,510
Default Re: Free new program Memoryze pinpoints malware code in live memory

It must be a gimmick
__________________
★AX 64 Time MachineCurrent Version 1.1.0.996 ★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Reserve Space|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #11  
Old November 15th, 2008, 01:25 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: Free new program Memoryze pinpoints malware code in live memory

Quote:
Originally Posted by EASTER
It must be a gimmick
It's not a gimmick if Jamie Butler is involved. I'll give it a spin tomorrow on my remaining XP partition and see what it does. It's a forensic tool that analyzes memory dumps; it's not a resident security app.

Nick
  #12  
Old November 15th, 2008, 01:43 AM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,510
Default Re: Free new program Memoryze pinpoints malware code in live memory

Quote:
Originally Posted by nick s
It's not a gimmick if Jamie Butler is involved. I'll give it a spin tomorrow on my remaining XP partition and see what it does. It's a forensic tool that analyzes memory dumps; it's not a resident security app.

Nick

Thanks

Pls offer some kind of activity that a user can either find reported or action performed even if it's a summary because it does absolutely nothing that i can find at all in it's current makeup.

EASTER
__________________
★AX 64 Time MachineCurrent Version 1.1.0.996 ★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Reserve Space|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #13  
Old November 15th, 2008, 02:55 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: Free new program Memoryze pinpoints malware code in live memory

Quote:
Originally Posted by EASTER
Thanks

Pls offer some kind of activity that a user can either find reported or action performed even if it's a summary because it does absolutely nothing that i can find at all in it's current makeup.

EASTER
It's usage is via the command line and the output is logged to .xml files. It's not point-and-click. The sample instructions are straightforward: Memoryze - Use Cases and Examples.

Nick
  #14  
Old November 15th, 2008, 03:03 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Free new program Memoryze pinpoints malware code in live memory

Quote:
It must be a gimmick
Hi EASTER, no it most certainly is not. I've used it often as with their first response which is a very nice reporting tool for networked or local machine. As nick s link above for instructions - default save to is Mandiant>Audits.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : November 15th, 2008 at 03:10 AM.
  #15  
Old November 25th, 2008, 04:43 PM
Jamie Butler's Avatar
Jamie Butler Jamie Butler is offline
Infrequent Poster
 
Join Date: Nov 2008
Posts: 1
Default Re: Free new program Memoryze pinpoints malware code in live memory

Thanks Nick for the kind words. We recognize that Memoryze's output is not very user friendly so one of my colleagues has coded a open source Python GUI for you to use. You can read about it on our new blog site: http://blog.mandiant.com/archives/50

I hope you find this and Memoryze useful.

Sincerely,
Jamie Butler
  #16  
Old November 25th, 2008, 05:48 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Free new program Memoryze pinpoints malware code in live memory

Jamie, thanks posting the link.

From the Audit viewer user guide pdf,
Quote:
Installation Perquisites
To run Audit Viewer, the user must have Python 2.5 or 2.6 and the wxPython library installed. The user can download these from:
python.org
wxpython.org/download.php#binaries

__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:48 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums