modhist

Modhist is a tool for generating a module load history from Windows crash dump files, enabling information security professionals to analyze system crashes and software failures effectively for troubleshooting or forensic investigation.

More about this tool
Emoji icon 2728.svg

1. Download and install Modhist as part of the Libfsntfs toolset from the GitHub repository. 2. Launch Modhist and specify the Windows crash dump file for analysis. 3. Run Modhist to generate the module load history from the crash dump. 4. Analyze the module load history to understand the sequence of module loading during crashes or failures effectively for troubleshooting or forensic investigation purposes.

Join Our Community

Stay ahead with the latest resource in cybersecurity.

Error. Your form has not been submittedEmoji
This is what the server says:
There must be an @ at the beginning.
I will retry
Reply

Frequently Asked Questions

Got questions? We've got answers.
Built on Unicorn Platform