From Collaborative RCE Tool Library
MemMAP
| Tool name: | MemMAP |
|
||
|---|---|---|---|---|
| Author: | a_d_13 | |||
| Website: | http://www.kernelmode.info/forum/viewtopic.php?f=11&t=383 | |||
| Current version: | 0.1.2 | |||
| Last updated: | October 9, 2010 | |||
| Direct D/L link: | Locally archived copy | |||
| License type: | Free | |||
| Description: | MemMAP is a tool inspired by j00ru's KernelMAP. I've written my own version with a couple more interesting features. A list follows: * More memory types included (kernel thread stacks and GDI objects) * Ability to visualize the memory of a user-mode process * Help dialog with description of memory types * Refresh feature When run without arguments, it will display a map of kernel memory. You can visualize a process by running "memmap -p <process id>". To refresh, press F5. To show help, press F1. The framed area is organized such that the top-left corner is address 0x80000000, and the bottom right corner is 0xFFFFF000 (or, for user-mode processes, 0x00000000 - 0x7FFFF000). Each pixel represents one page of memory (4096 bytes). |
|||
| Related URLs: | No related URLs have been submitted for this tool yet | |||
| Screenshot: |
|---|
![]() |
Feed containing all updates for this tool.
(please also edit it if you think it fits well in some additional category, since this can also be controlled)

You are welcome to add your own useful notes about this tool, for others to see!