Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
DAMM — Analisi differenziale del malware in memoria | Kitploit
Strumenti/GitHubGitHub/504ensicslabs/damm
Memory ForensicsAnalisi delle VulnerabilitàInformatica ForenseAnalisi MalwareDigital ForensicsRisposta agli IncidentiArchived
GitHub504ensicslabs/damm

DAMM

Analisi differenziale del malware in memoria

Vedi Repository
21547169 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Sito web

DAMM

Uno strumento open source di analisi della memoria basato su Volatility. È pensato come un banco di prova per tecniche interessanti e innovative da mettere a disposizione della community. Queste tecniche tentano di accelerare il processo di investigazione attraverso la riduzione dei dati e la codifica di conoscenze esperte.

Table of Contents

  • Caratteristiche
  • Utilizzo
    • Plugin supportati
    • Esempio
    • Differenze
    • Manipolazione ID univoci
    • Filtraggio
    • Avvertenze
  • Infine

Caratteristiche

  • ~30 plugin di Volatility combinati in ~20 plugin DAMM (ad es. pslist, psxview e altri elementi sono combinati in un plugin 'processes')
  • Può eseguire più plugin in un'unica invocazione
  • La possibilità di salvare i risultati dei plugin in database SQLite per conservazione o per analisi "cached"
  • Un sistema di filtri/tipi che consente di filtrare facilmente per attributi come i pid per vedere tutte le informazioni relative a un determinato processo e il matching esatto o parziale per le stringhe, ecc.
  • La possibilità di mostrare le differenze tra due database di risultati per macchine uguali o simili e di gestire dalla riga di comando il funzionamento del confronto
  • La capacità di avvisare su determinati tipi di comportamento sospetto
  • Output per terminale, tsv o grepable

Utilizzo ```

NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:

python damm.py | less -S (for default output format)

python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]

DAMM v1.0 Beta

optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).

### Plugin supportati <a name="plugins"/>

Vedi #python damm.py --info

apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers


### Esempio <a name="example"/>
Fornisci un profilo come in Volatility, un'immagine di memoria e un elenco di plugin da eseguire (o 'all') per ottenere l'output del terminale:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset   	name           	pid 	ppid	prio	image_path_name                                                              	create_time                 	exit_time                   	threads	session_id	handles	is_wow64	pslist	psscan	thrdproc	pspcid	csrss	session	deskthrd	command_line                                                                                                                                                                                                                                                                
0x25c8830	System         	4   	0   	8   	                                                                             	                            	                            	59     	          	403    	False   	True  	True  	True    	True  	False	False  	False
0x225ada0	alg.exe        	188 	668 	8   	C:\WINDOWS\System32\alg.exe                                                  	2010-10-29 17:09:09 UTC+0000	                            	6      	0         	107    	False   	True  	True  	True    	True  	True 	True   	True    	C:\WINDOWS\System32\alg.exe
0x2114938	ipconfig.exe   	304 	968 	8   	                                                                             	2011-06-03 04:31:35 UTC+0000	2011-06-03 04:31:36 UTC+0000	0      	0         	       	False   	True  	True  	False   	True  	False	False  	False
0x2086978	TSVNCache.exe  	324 	1196	8   	C:\Program Files\TortoiseSVN\bin\TSVNCache.exe                               	2010-10-29 17:11:49 UTC+0000	                            	7      	0         	54     	False   	True  	True  	True    	True  	True 	True   	True    	"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020	smss.exe       	376 	4   	11  	\SystemRoot\System32\smss.exe                                                	2010-10-29 17:08:53 UTC+0000	                            	3      	          	19     	False   	True  	True  	True    	True  	False	False  	False   	\SystemRoot\System32\smss.exe
...

Per rendere persistenti questi risultati in un database SQLite, basta fornire un nome file per il database:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db

Questo stamperà i risultati sul terminale oltre a salvarli in 'my_results.db'

Per rivedere i risultati:```
python damm.py -p processes --db my_results.db

(Nota che non è più necessaria l'immagine di memoria né specificare un profilo: l'elenco verrà generato quasi istantaneamente, indipendentemente da quanto tempo ha richiesto l'elaborazione originale.)

Se in seguito desideri vedere i processi e altri plugin:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db

Farà:
 1. consultare il db per l'output 'processes'
 2. eseguire i plugin 'dlls' e 'modules'
 3. mostrare i risultati
 4. salvare i nuovi risultati nel db

Dopo aver salvato alcuni dati in un db, puoi interrogarlo con l'opzione -q```
python damm.py -q --db my_results.db 
profile:	WinXPSP2x86
memimg:	WinXPSP2x86/stuxnet.vmem
COMPUTERNAME:	JAN-DF663B3DBF1
plugins:	processes dlls modules

I plugin hanno attributi che possono avere tipi per il filtraggio, ad es. per i processi: (usa --info per vedere tutti gli attributi dei plugin)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd

Questi attributi e tipi possono essere sfruttati dalle funzioni di differenziazione e filtraggio di DAMM

### Differenziazione <a name="differencing"/>
Per utilizzare il motore di differenziazione, crea 2 database da 2 immagini di memoria distinte, ad esempio una prima e una dopo l'esecuzione di un malware```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db

Quindi usa l'opzione --diff per il db di base (qui, il db dell'immagine di memoria non infetta).``` python damm.py -p processes --db after.db --diff before.db

Scarica lo strumento