Who needs WindowsSCOPE tools? Must-have for incident responders for memory forensics and cyber security professionals to capture, decompile, disassemble, analyze and graph the internals of a Windows system and everything it runs directly from memory. They are also valuable tools for learning operating systems internals and development. See our screen shots, videos, blogs. Register to receive exclusive pre-release memory forensics and cyber analysis tools.
Why you'll love it. You'll master the Windows kernel; disassemble, decompile, reverse engineer and/or graph interactively control flow in the kernel/user space; verify applications' behavior in memory, perform live digital and memory forensics, cyber crime analysis, and cyber attack detection. Register to watch the new use cases including detecting the Shadow Walker rootkit security attack.
Which version? Choose from Pro (Student or Standard), Law Enforcement, Live, or Enterprise - 32/64 bits XP, Vista, or 7. Features:
- View kernel data structures SSDT,IDT,..., ports and registry
- In-depth view of the paging system; see what is paged in
- In-depth DLLs, drivers and software analysis, forensics data
- Disassemble, decompile for cyber analysis and defense
- Memory forensics with interactive control flow graph
- Hardware-assisted live forensics analysis (Law Enforcement)
- Manual / automated annotations for cyber analyses & forensics
- Scheduled security snapshots, multi-site access (Enterprise)
- Real-time monitor from mobile phone (Live)
|
|
|
http://www.windowsscope.com/index.php?option=com_content&view=article&id=80&Itemid=49 |
|