Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Post-Mortem RAM Forensics - CanSecWest
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>CanSecWest</strong>2007<br />
34<br />
• Ready….go!<br />
PoC: Demo<br />
– MEMORY.DMP format<br />
– dd –style<br />
– Processes<br />
– Threads<br />
– Exe extraction<br />
• Virtual memory layer required<br />
• Finished coding this during Adam<br />
Laurie’s talk yesterday – consider BETA<br />
VIDAS