Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>CanSecWest</strong>2007<br />
31<br />
• Create Images<br />
C<br />
–ddexample<br />
PoC: Demo<br />
• trusted binary’ (live CD, statically linked)<br />
• external Mass storage container<br />
• ‘raw’ type<br />
– Forced Crash condition<br />
• registry keys<br />
• 3rd party testing tool<br />
• External Mass storage container<br />
• proprietary DMP format created on reboot<br />
• Use PERL to parse through a ton of data<br />
– Practical Extraction and Reporting Language<br />
VIDAS