Heap Inspector™ allows an investigator to visualize and search data stored in application heap memory. This is a simple yet extremely powerful ability, particularly in the context of host-level forensics. I will discuss two specific use cases: detecting heap spray attacks (post-mortem) and searching for personally identifiable information (PII).
The Terms of Use for this software are subject to the licensing and terms outlined in the freeware app.
Developer: | FireEye |
Resources: | Free Software Downloads |
FireEye Blog |
Version: | 1.1 |
Platform: | Windows |
Requirements: | Windows XP, Windows Vista, Windows 7 (32-bit and 64-bit) |
Size: | 0.3 MB |
MD5: | 180F3AC908CA4654004D534624B0396C |
SHA1: | 2A9AD398BC07BF66195E3FF78E39CC3B2784EABE |