Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>CanSecWest</strong>2007<br />
28<br />
PoC: Virtual Memory<br />
Page Directory Index Page Table Index Byte Offset<br />
Page Directory<br />
PDI Entry<br />
Shown without PAE enabled<br />
Virtual Address<br />
Page Table<br />
PTI Entry<br />
Adapted from Windows Internals : Solomon and Rossinovich<br />
See also Intel Software Developers Manuals<br />
Physical Memory<br />
Page<br />
Physical<br />
Page<br />
Byte<br />
VIDAS