02.11.2014 Views

slides

slides

slides

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Useful Observations for<br />

Forensics<br />

●<br />

●<br />

●<br />

●<br />

All user processes have page tables<br />

●<br />

Note: it is possible for an advanced attacker to change the mode of<br />

the CPU so that paging is disabled<br />

Page directories and page tables can be identified<br />

using a set of known rules/patterns<br />

Other x86 data structures can also be identified with<br />

similar methods<br />

Key point: page table identification can be used<br />

to locate hidden processes

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!