@@ -50,27 +50,27 @@ Download the latest version of **MemProcFS-Analyzer** from the [Releases](https:
5050## Usage
5151Launch Windows PowerShell (or Windows PowerShell ISE or Visual Studio Code w/ PSVersion: 5.1) as Administrator and open/run MemProcFS-Analyzer.ps1.
5252
53- ![ File-Browser] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/01.png )
53+ ![ File-Browser] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/01.png )
5454** Fig 1:** Select your Memory Snapshot and select your pagefile.sys (Optional)
5555
56- ![ Auto-Install] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/02.png )
56+ ![ Auto-Install] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/02.png )
5757** Fig 2:** MemProcFS-Analyzer auto-installs dependencies (First Run)
5858
59- ![ Microsoft-Internet-Symbol-Store] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/03.png )
59+ ![ Microsoft-Internet-Symbol-Store] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/03.png )
6060** Fig 3:** Accept Terms of Use (First Run)
6161
62- ![ MemProcFS] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/04.png )
62+ ![ MemProcFS] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/04.png )
6363** Fig 4:** If you find MemProcFS useful, please become a sponsor at: https://github.com/sponsors/ufrisk
6464
6565![ Mounted] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2/Screenshots/05.png )
6666** Fig 5:** You can investigate the mounted memory dump by exploring drive letter
6767
68- ![ Auto-Update] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/06.png )
68+ ![ Auto-Update] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/06.png )
6969** Fig 6:** MemProcFS-Analyzer checks for updates (Second Run)
7070
7171Note: It's recommended to uncomment/disable the "Updater" function after installation. Check out the "Main" in the bottom of the script.
7272
73- ![ FindEvil] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/07.png )
73+ ![ FindEvil] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/07.png )
7474** Fig 7:** FindEvil feature and additional analytics
7575
7676![ Processes] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2/Screenshots/08.png )
@@ -118,7 +118,7 @@ Note: It's recommended to uncomment/disable the "Updater" function after install
118118![ ELK-Timeline] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2/Screenshots/22.png )
119119** Fig 22:** Happy ELK Hunting!
120120
121- ![ Secure-Archive-Container] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2 /Screenshots/23.png )
121+ ![ Secure-Archive-Container] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0780ec4a5fc62219e12791456f5f1e38d5b10b1a /Screenshots/23.png )
122122** Fig 23:** Multi-Threaded ClamAV Scan to help you finding evil! ;-)
123123
124124![ Message-Box] ( https://github.com/evild3ad/MemProcFS-Analyzer/blob/0bb85b553644a29675e4116133e7346b080d07a2/Screenshots/24.png )
0 commit comments