13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

25<br />

Cross Volatility Comparison<br />

• Ideally, the analysis of volatile data stores<br />

can be aided (in practice) by information<br />

gleamed from non-volatile stores<br />

– Pagefile to <strong>RAM</strong> comparison (verification?<br />

Unification?)<br />

• A ‘side effect’ of crash dumps is that the page file is<br />

over written.<br />

• The formation of the DMP file is actually an<br />

interesting process…<br />

– Event log correlation<br />

– What if the disk shows Windows XP, but <strong>RAM</strong><br />

shows Linux structures?<br />

–etc<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!