13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

33<br />

PoC: Demo<br />

• On a removable hard drive<br />

– raw style captures via helix dd<br />

– Crash style captures via<br />

nonmyfault.exe & crashdump<br />

• Just typical PERL<br />

– Activestate<br />

– Cross platform<br />

• The idea is to replicate as much or<br />

more information that Windows<br />

Task Manager<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!