CF2 04 - Memory File.pdf

(3244 KB) Pobierz
Forensics II
Memory forensics 101
Dumpers and analysers
GNU/Linux and Android
File analysis (short)
Memory forensics I
Memory forensics II
Memory forensics III
• Dump physical memory (RAM), why?
– Current running processes and terminated processes
– Open TCP/UDP ports/raw sockets/active connections
– Memory mapped files
• Executable image, shared, objects (modules/drivers), text files
– Caches
• Web addresses, typed commands, passwords, clipboards, SAM
database, edited files
– Hidden data, encryption keys and many more
– Problematic… system is alive
• Page/swap file, new process etc., Locards exchange principle
• Analyze the RAM
– Enumerate different program structures, signature based carving,
find text strings, virus scans, network connections etc. ...
Memory forensics IV
Microsoft Portable Executable and Common Object File Format Specification
http://www.microsoft.com/whdc/system/platform/firmware/PECOFF.mspx
• PE format
• PEview
VA
File offset
Zgłoś jeśli naruszono regulamin