Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>CanSecWest</strong>2007<br />
39<br />
Future work<br />
(memory, not process specific)<br />
• File cache<br />
– Delayed write to disk, usually for<br />
priority reasons<br />
• Network connections<br />
– Tied to processes<br />
• Video card?<br />
– Some malware is executing directly<br />
from video card memory<br />
VIDAS