ai-agent

MemProcFS-Analyzer: Simplify DFIR

Get automated forensic analysis of Windows memory dumps with MemProcFS-Analyzer, a tool for startup founders in digital forensics and incident response.
728 stars78 forksPowerShellGuide quality 8/10Updated 5/2/2026100% free · open source
What it does

MemProcFS-Analyzer provides automated forensic analysis of Windows memory dumps to help identify potential security threats and understand system behavior

When to use it
  • When analyzing a Windows system for malware or unauthorized access
  • During incident response to understand the scope of a security breach
  • To inspect a Windows system's memory for suspicious activity or configuration issues
Ready-to-paste prompt
.\MemProcFS-Analyzer.ps1 -f C:\path\to\memory.dmp -o C:\path\to\output
Heads up: The system must have PowerShell 3 or later installed, and the MemProcFS-Analyzer script must be run with administrative privileges to access the Windows memory dump files
Saves to your device
Use with Claude
New

Skip the builder — one click puts this in Claude, Cursor, Antigravity and more.

✅ Light setup

Installs with a command or two; your AI agent can do it for you.

Try it instantly — no install
Claude Code
mkdir -p ~/.claude/skills/memprocfs-analyzer && curl -fsSL https://workflowstacks.com/api/skills/memprocfs-analyzer/claude-skill -o ~/.claude/skills/memprocfs-analyzer/SKILL.md
Open in another AI app

Opens the app with this repo with the prompt ready to go — no copy-paste needed.

Connect the whole catalog (MCP)
claude mcp add --transport http workflowstacks https://workflowstacks.com/api/mcp

Adds a WorkflowStacks connector to Claude Code: search and load any skill here by chatting.

Quick Actions
Details
Creator
LETHAL-FORENSICS
Language
PowerShell
Category
ai-agent
Published
5/15/2021

Are you the creator of this tool? Claim your listing → and earn 85% of every sale.