Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>CanSecWest</strong>2007<br />
33<br />
PoC: Demo<br />
• On a removable hard drive<br />
– raw style captures via helix dd<br />
– Crash style captures via<br />
nonmyfault.exe & crashdump<br />
• Just typical PERL<br />
– Activestate<br />
– Cross platform<br />
• The idea is to replicate as much or<br />
more information that Windows<br />
Task Manager<br />
VIDAS