/Xavier_MemoryAnalysis_Framework

Xavier Framework is a user interface wrapper built on top of the Volatility(c) memory forensics framework.

Primary LanguageJavaGNU General Public License v3.0GPL-3.0

Xavier_MemoryAnalysis_Framework

Xavier Framework is a user interface wrapper built on top of the Volatility(c) memory forensics framework.

Getting Started

The latest version of Volatility can be downloaded from https://www.volatilityfoundation.org/releases Please download and extract the latest Volatility binary file first before running Xavier. After Volatility is ready on your machine, run Xavier and point it to the Volatility binary (you'll be prompted). Dump a memory image file (using a separate memory acquisition tool) to begin analysis. You can use the Add Search Image Tab to perform keyword searches on any image file you load into Xavier.

Memory Acquisition

There are multiple programs useful for acquiring a memory image for analysis. The following tools were very effective to acquire a memory image:

Memory Analysis

Once you have a memory image, you can perform analysis using Xavier (that scripts commands to Volatility) and helps to provide additional analysis for the investigator. From Xavier, executing each plugin creates a separate tab to view the analysis results. An output file is also created to reference output at a later date.

Additional Memory Analysis Tools Include:

Volatility, Mandiant's Redline, Rekall, Autopsy, FTK Imager, OSForensics

Memory Image CTFs to Analyze:

Below are links to memory images/challenges/writeups I liked and would like to reference for you to use and enhance your knowledge.

Note: These resources are maintained by others, thus, I would expect some links will die over time, if so, please contact me to update.

Disclaimer:

This is the initial beta release of Xavier. So far, I've only developed and tested this version of Xavier on a Windows OS machines... I'll come back later and ensure it is compatible on *nix versions.

Questions/Updates?

If you have any questions or update suggestions, please feel free to contact me.

Cheers!

-Solomon Sonya Twitter: @Carpenter1010