SysAnalyzer

SysanalyzerSysAnalyzer is an automated malcode run time analysis application that monitors various aspects of system and process states. SysAnalyzer was designed to enable analysts to quickly build a comprehensive report as to the actions a binary takes on a system. SysAnalyzer can automatically monitor and compare: Running Processes, Open Ports, Loaded Drivers, Injected Libraries, Key Registry Changes, APIs called by a target process, File Modifications, HTTP, IRC, and DNS traffic. SysAnalyzer also comes with a ProcessAnalyzer tool which can perform the following tasks: Create a memory dump of target process, parse memory dump for strings, parse strings output for exe, reg, and url references and scan memory dump for known exploit signatures.

Homepage

You might be interested in these as well:
  • No related posts

One Response to 'SysAnalyzer'

Subscribe to comments with RSS or TrackBack to 'SysAnalyzer'.

  1. Dessy said,

    on February 21st, 2007 at 8:22 pm

    This is an extremly good tool to analyze malware. It shows you the running processes, the open ports etc.

Post a review

Powered by WP Hashcash