13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CanSecWest</strong>2007<br />

31<br />

• Create Images<br />

C<br />

–ddexample<br />

PoC: Demo<br />

• trusted binary’ (live CD, statically linked)<br />

• external Mass storage container<br />

• ‘raw’ type<br />

– Forced Crash condition<br />

• registry keys<br />

• 3rd party testing tool<br />

• External Mass storage container<br />

• proprietary DMP format created on reboot<br />

• Use PERL to parse through a ton of data<br />

– Practical Extraction and Reporting Language<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!