MemProcFS - This Changes Everything

Imagine being able to "mount" memory as if it were a disk image. With a single command, MemProcFS will create a virtual file system representing the processes, file handles, registry, $MFT, and more. The tool can be executed against a memory dump, or run against memory on a live system. This is a game changer for memory forensics! ** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ** 📖 Chapters 00:00 - Intro 01:42 - Installation 02:41 - Demo 🛠 Resources MemProcFS: The Memory Process File System: https://github.com/ufrisk/MemProcFS #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics #MemoryForensics