13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CanSecWest</strong>2007<br />

39<br />

Future work<br />

(memory, not process specific)<br />

• File cache<br />

– Delayed write to disk, usually for<br />

priority reasons<br />

• Network connections<br />

– Tied to processes<br />

• Video card?<br />

– Some malware is executing directly<br />

from video card memory<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!