Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>CanSecWest</strong>2007<br />
14<br />
• systeminfo.exe<br />
• Psinfo<br />
• netstat,<br />
• date,<br />
• Time<br />
• psuptime,<br />
• net statistics<br />
• pulist,<br />
• tlist,<br />
• pslist,<br />
• listdllsdir,<br />
• afind,<br />
• macmatch,<br />
• autoruns,<br />
Minimize impact<br />
• handle,<br />
• pclipnet<br />
• users,<br />
• psloggedon,<br />
• ntlast,<br />
• Dumpusers<br />
• ipconfig,<br />
• fport,<br />
• psservice,<br />
• promiscdetect,<br />
• netstat,<br />
• nbstat,<br />
• net,<br />
• arp<br />
vs<br />
dd<br />
(or similar)<br />
…and the one on the right potentially has more information!!<br />
Nolan, O’Sullivan, Branson, Waits. First Responders Guide to Computer <strong>Forensics</strong>.<br />
Carnegie Mellon University 2005.<br />
VIDAS