home

scan memory dump for EPROCESS tags · rebuild process tree

Drop .dmp / .vmem / .raw memory dump
heuristic scan for Windows EPROCESS pool tags
drop a Windows memory dump (.dmp, .vmem, .raw, .mem)
ready