/Winpmem-FrontEnd

A front end for winpmem

Primary LanguageAutoIt

Winpmem-FrontEnd

A front end for winpmem, written in Autoit. Use Autoit compiler to compile from source PmemFrontend.au3 file.

Usage:

Place PmemFrontend.exe in the same folder as winpmem-2.1.post4.exe (https://github.com/google/rekall/releases)

Run as admin and click "Start"

A txt file and folder will be created using the machine name. The text file will contain machine host information. The folder will contain the memory and driver dump.

PmemFrontend.exe hashes:

MD5: 6fccbcd00a30c3b89fe4da2b5a6a795f

SHA1: 53d4b8bfe64007bfe606b191e61b876e57408e68