evild3ad / MemProcFS-Analyzer

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
https://lethal-forensics.com
GNU General Public License v3.0
462 stars 53 forks source link

JSON Formatting #32

Closed Liebershnitzel closed 4 months ago

Liebershnitzel commented 8 months ago

Hi, my team typically uses splunk which favors JSON formatting. It would be extremely beneficial to us if you could add a JSON option on top of the CSV option you already provide. Fantastic addition to the already amazing MemProcFS project, thank you for creating this.

evild3ad commented 4 months ago

You can use for example the 'FS_Forensic_JSON' output by MemProcFS: https://github.com/ufrisk/MemProcFS/wiki/FS_Forensic_JSON

It is currently not planned to add JSON formatted output files to the MemProcFS-Analyzer. Sorry!