Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
DAMM — メモリ内のマルウェアの差分分析 | Kitploit
ツール/GitHubGitHub/504ensicslabs/damm
メモリフォレンジック脆弱性分析フォレンジックマルウェア分析デジタルフォレンジックインシデントレスポンスArchived
GitHub504ensicslabs/damm

DAMM

メモリ内のマルウェアの差分分析

リポジトリを見る
21547169年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

DAMM

Volatilityの上に構築されたオープンソースのメモリ分析ツールです。コミュニティに提供するための興味深い新しい技術の試験場となることを目的としています。これらの技術は、データ削減と専門知識の形式化を通じて調査プロセスを高速化するための試みです。

目次

  • 機能
  • 使い方
    • 対応プラグイン
    • 例
    • 差分
    • 一意IDの操作
    • フィルタリング
    • 警告
  • 最後に

機能

  • 約30のVolatilityプラグインが約20のDAMMプラグインに統合されています(例:pslist、psxview、その他の要素は'processes'プラグインに統合されています)
  • 1回の呼び出しで複数のプラグインを実行できます
  • プラグインの結果をSQLiteデータベースに保存して、保存用または「キャッシュ」分析用に利用するオプション
  • pidなどの属性を簡単にフィルタリングして、特定のプロセスに関連するすべての情報を確認したり、文字列の完全一致または部分一致を行ったりできるフィルタリング/型システム
  • 同一または類似のマシンに対する2つの結果データベース間の差分を表示し、コマンドラインから差分の動作を操作する機能
  • 特定の種類の疑わしい動作について警告する機能
  • ターミナル、TSV、またはgrep可能な出力

使い方 ```

NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:

python damm.py | less -S (for default output format)

python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]

DAMM v1.0 Beta

optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).

### 対応プラグイン <a name="plugins"/>

参照 #python damm.py --info

apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers

### 例 <a name="example"/>
Volatility と同様に、プロファイル、メモリイメージ、実行するプラグインのリスト (または 'all') を指定すると、ターミナル出力が得られます:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset   	name           	pid 	ppid	prio	image_path_name                                                              	create_time                 	exit_time                   	threads	session_id	handles	is_wow64	pslist	psscan	thrdproc	pspcid	csrss	session	deskthrd	command_line                                                                                                                                                                                                                                                                
0x25c8830	System         	4   	0   	8   	                                                                             	                            	                            	59     	          	403    	False   	True  	True  	True    	True  	False	False  	False
0x225ada0	alg.exe        	188 	668 	8   	C:\WINDOWS\System32\alg.exe                                                  	2010-10-29 17:09:09 UTC+0000	                            	6      	0         	107    	False   	True  	True  	True    	True  	True 	True   	True    	C:\WINDOWS\System32\alg.exe
0x2114938	ipconfig.exe   	304 	968 	8   	                                                                             	2011-06-03 04:31:35 UTC+0000	2011-06-03 04:31:36 UTC+0000	0      	0         	       	False   	True  	True  	False   	True  	False	False  	False
0x2086978	TSVNCache.exe  	324 	1196	8   	C:\Program Files\TortoiseSVN\bin\TSVNCache.exe                               	2010-10-29 17:11:49 UTC+0000	                            	7      	0         	54     	False   	True  	True  	True    	True  	True 	True   	True    	"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020	smss.exe       	376 	4   	11  	\SystemRoot\System32\smss.exe                                                	2010-10-29 17:08:53 UTC+0000	                            	3      	          	19     	False   	True  	True  	True    	True  	False	False  	False   	\SystemRoot\System32\smss.exe
...

これらの結果をSQLiteデータベースに永続化させるには、データベースのファイル名を指定するだけです:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db

これにより、結果がターミナルに出力されるとともに、'my_results.db' に保存されます。

結果を再度表示するには:```
python damm.py -p processes --db my_results.db

(メモリイメージやプロファイルを指定する必要がなくなり、元の処理にどれだけ時間がかかったかに関係なく、リストはほぼ即座に表示されることに注意してください。)

後でプロセスやその他のプラグインを確認したい場合は:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db

実行内容:
 1. db で 'processes' 出力を参照する
 2. 'dlls' および 'modules' プラグインを実行する
 3. 結果を表示する
 4. 新しい結果を db に保存する

db にデータを保存したら、-q スイッチでクエリを実行できます。```
python damm.py -q --db my_results.db 
profile:	WinXPSP2x86
memimg:	WinXPSP2x86/stuxnet.vmem
COMPUTERNAME:	JAN-DF663B3DBF1
plugins:	processes dlls modules

プラグインには、フィルタリング用の型を持つ属性があります。例: プロセス向け: (すべてのプラグイン属性を確認するには --info を使用してください)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd

これらの属性とタイプは、DAMM の差分処理およびフィルタリング機能によって活用できます。

### 差分 <a name="differencing"/>
差分エンジンを使用するには、たとえばマルウェアの実行前と実行後の 2 つの異なるメモリイメージから、2 つのデータベースを作成します。```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db

次に、ベースラインのDB(ここでは、感染していないメモリイメージからのDB)に対して --diff オプションを使用します。``` python damm.py -p processes --db after.db --diff before.db

ツールをダウンロード