From Collaborative RCE Tool Library

Jump to: navigation, search

MemMAP

Tool name: MemMAP
Rating: 0.0 (0 votes)
Author: a_d_13                        
Website: http://www.kernelmode.info/forum/viewtopic.php?f=11&t=383
Current version: 0.1.2
Last updated: October 9, 2010
Direct D/L link: Locally archived copy
License type: Free
Description: MemMAP is a tool inspired by j00ru's KernelMAP. I've written my own version with a couple more interesting features. A list follows:

* More memory types included (kernel thread stacks and GDI objects)
* Ability to visualize the memory of a user-mode process
* Help dialog with description of memory types
* Refresh feature

When run without arguments, it will display a map of kernel memory. You can visualize a process by running "memmap -p <process id>". To refresh, press F5. To show help, press F1.

The framed area is organized such that the top-left corner is address 0x80000000, and the bottom right corner is 0xFFFFF000 (or, for user-mode processes, 0x00000000 - 0x7FFFF000). Each pixel represents one page of memory (4096 bytes).
Related URLs: No related URLs have been submitted for this tool yet


Screenshot:
Screenshot of MemMAP


RSS feed Feed containing all updates for this tool.

You are welcome to add your own useful notes about this tool, for others to see!



If you find that any information for the tool above is missing, outdated or incorrect, please edit it!
(please also edit it if you think it fits well in some additional category, since this can also be controlled)


Views
Category Navigation Tree
   Needs New Category  (3)