13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

28<br />

PoC: Virtual Memory<br />

Page Directory Index Page Table Index Byte Offset<br />

Page Directory<br />

PDI Entry<br />

Shown without PAE enabled<br />

Virtual Address<br />

Page Table<br />

PTI Entry<br />

Adapted from Windows Internals : Solomon and Rossinovich<br />

See also Intel Software Developers Manuals<br />

Physical Memory<br />

Page<br />

Physical<br />

Page<br />

Byte<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!