13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CanSecWest</strong>2007<br />

34<br />

• Ready….go!<br />

PoC: Demo<br />

– MEMORY.DMP format<br />

– dd –style<br />

– Processes<br />

– Threads<br />

– Exe extraction<br />

• Virtual memory layer required<br />

• Finished coding this during Adam<br />

Laurie’s talk yesterday – consider BETA<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!