13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

43<br />

Question #1 from the<br />

Audience<br />

• So how do you recommend that I<br />

implement <strong>RAM</strong> into my investigations?<br />

– Officially I’m probably not supposed to<br />

answer that<br />

• The whole I’m not a lawyer and don’t play one on<br />

TV thing<br />

• The whole I’m an Academic not a practitioner thing<br />

– That said: If the situation allows, maybe the<br />

best way is to:<br />

• arrive on scene<br />

• get ready (BIOS cheat sheet, dd on bootable CD)<br />

• pull plug ***<br />

• plug back in immediately ***<br />

• boot to CD<br />

• copy <strong>RAM</strong><br />

• image disk as normal<br />

• take both back with you<br />

***Or maybe it’s via dd on a USB mass storage – copy w/o unplugging, time / results VIDAS will tell

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!