|  |  |  |  |  |  |
 
MALCODE ANALYSIS SOFTWARE TOOLS
MALCODE ANALYSIS SOFTWARE TOOLS
MALCODE ANALYSIS SOFTWARE TOOLS
 Home // Software // Malcode Analysis Software Tools
Email This Page URL  Print This Page
//  SysAnalyzer
  seperator  open/close
01.19.07
Author: David Zimmer
Size: 1.9mb
MD5: B75F17199AB6EB781595758C51413EF3

SysAnalyzer is an automated malcode run time analysis application that monitors various aspects of system and process states.

SysAnalyzer was designed to enable analysts to quickly build a comprehensive report as to the actions a binary takes on a system.

Updated 1/19/07: added known file db

SysAnalyzer can automatically monitor and compare:
  • Running Processes
  • Open Ports
  • Loaded Drivers
  • Injected Libraries
  • Key Registry Changes
  • APIs called by a target process
  • File Modifications
  • HTTP, IRC, and DNS traffic
SysAnalyzer also comes with a ProcessAnalyzer tool which can perform the following tasks:
  • Create a memory dump of target process
  • parse memory dump for strings
  • parse strings output for exe, reg, and url references
  • scan memory dump for known exploit signatures
Full GPL source for SysAnalyzer is included in the installation package:
Overview  |   Video Tour

Download  |  License 

//  Malcode Analysis Pack
  seperator  open/close
11.13.06
//  HookExplorer
  seperator  open/close
03.16.06
//  Multipot
  seperator  open/close
08.17.05