CF2 04 - Memory File.pdf
(
3244 KB
)
Pobierz
Forensics II
Memory forensics 101
Dumpers and analysers
GNU/Linux and Android
File analysis (short)
Memory forensics I
Memory forensics II
Memory forensics III
• Dump physical memory (RAM), why?
– Current running processes and terminated processes
– Open TCP/UDP ports/raw sockets/active connections
– Memory mapped files
• Executable image, shared, objects (modules/drivers), text files
– Caches
• Web addresses, typed commands, passwords, clipboards, SAM
database, edited files
– Hidden data, encryption keys and many more
– Problematic… system is alive
• Page/swap file, new process etc., Locards exchange principle
• Analyze the RAM
– Enumerate different program structures, signature based carving,
find text strings, virus scans, network connections etc. ...
Memory forensics IV
•
Microsoft Portable Executable and Common Object File Format Specification
–
http://www.microsoft.com/whdc/system/platform/firmware/PECOFF.mspx
• PE format
• PEview
VA
File offset
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
CF2 01 - Course Intro.pdf
(2399 KB)
CF2 04 - Memory File.pdf
(3244 KB)
CF2 02 - Carving.pdf
(1537 KB)
CF2 07 - File Analysis.pdf
(2134 KB)
CF2 02 - Linux Filesystems.pdf
(633 KB)
Inne foldery tego chomika:
Computer Forensics 1
Exploration of Mobile and Embedded Systems
Incident Response
Malware
Reports
Zgłoś jeśli
naruszono regulamin