Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>CanSecWest</strong>2007<br />
41<br />
Food for thought:<br />
• But the cases I have don’t require<br />
all this stuff!<br />
– The hacker defense will bear it’s face<br />
eventually<br />
– <strong>RAM</strong> imaging is going to be ‘industry<br />
standard’ it’s just a matter of time<br />
– You may be more likely to have a<br />
Rootkit that you think*<br />
*You’ve heard of Sony right?<br />
VIDAS