Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>CanSecWest</strong>2007<br />
5<br />
Evidence Volatility<br />
• Registers (more volatile)<br />
• Caches<br />
• Memory, process table, routing<br />
table, arp cache, etc<br />
• Temp file systems<br />
• File system / Disk Block<br />
• Archival Media (less volatile)<br />
Check out RFC 3227:<br />
“Guidance for Evidence Collection and Archiving<br />
VIDAS