22.03.2013 Views

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Live Response<br />

Live Incident Response<br />

Collect Volatile Data<br />

Collect Non-Volatile Data<br />

© <strong>Below</strong> <strong>Gotham</strong> <strong>Labs</strong>, 2009<br />

Time, NIC parameters, loaded modules, etc.<br />

RAM & ROM Acquisition<br />

Hardware-Based<br />

Software-Based<br />

External Port Scan (e.g. nmap)<br />

User account info, installed patches, etc.<br />

Live Disk Imaging<br />

30

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!