13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CanSecWest</strong>2007<br />

21<br />

EPROCESS<br />

• The EPROCESS structure is<br />

fundamental<br />

• Among other information, PID, Creation /<br />

Deletion times, executing image name,<br />

priority, etc<br />

• Used for scheduling<br />

– …well, sort of <br />

• Pointers to previous and next process<br />

(double linked list)<br />

– Not particularly helpful in this case, as ‘rogue’<br />

and ‘old’ processes are desirable to find as<br />

well<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!