13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CanSecWest</strong>2007<br />

5<br />

Evidence Volatility<br />

• Registers (more volatile)<br />

• Caches<br />

• Memory, process table, routing<br />

table, arp cache, etc<br />

• Temp file systems<br />

• File system / Disk Block<br />

• Archival Media (less volatile)<br />

Check out RFC 3227:<br />

“Guidance for Evidence Collection and Archiving<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!