by moyix
The VAD tools are a set of scripts for working with Virtual Address Descriptor structures in dumps of Windows physical memory to provide detailed information about a process's memory allocations to a forensic investigator.
I've just uploaded the initial release of the VAD Tools. The accompanying paper has been left out of this release at the request of DFRWS; I will upload it here once the paper is published. Download and enjoy!
Initial release. Pre-release change notes can be found in Subversion.
Copyright © 2009 SourceForge, Inc. All rights reserved. Terms of Use